Apple Caps Open Bug-Bounty Reports After Surge in Unvalidated AI Findings

Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue. Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity […]

Written By
LT
Liz Ticong
Aug 5, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue.

Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity for additional or urgent findings.

AI tools can uncover legitimate flaws and generate convincing false alarms at similar speed. A volume-based limit may help reviewers regain control, but credible reports can be delayed alongside the junk.

AI-assisted findings still require proof

AI slop reports can look polished while relying on hallucinated, theoretical, or poorly tested findings. These submissions reach bug-bounty programs without enough evidence for reviewers to reproduce the issue or assess its impact.

Apple’s bounty guidelines require a working exploit or reliable proof of concept, numbered reproduction steps and an explanation of the security impact. Under those rules, the company can pause a researcher’s open reports for 180 days after repeated unvalidated AI submissions. More than two pauses can lead to removal from the program.

AI assistance remains eligible when researchers test and verify the findings. Recent security advisories credit work involving Anthropic’s Claude and OpenAI’s Codex Security, adding to evidence that AI-assisted vulnerability research can produce valid discoveries.

A valid Mac flaw hits the submission cap

Financial Times brought the restrictions to public attention after Milan-based security startup Bynario reached its open-report limit. Its seven-person team said ChatGPT helped identify more than 50 potential macOS issues in three weeks.

One finding involved macOS Screen Sharing and could expose protected data or create files with root privileges when legacy Virtual Network Computing password authentication was enabled, according to the startup. Quota restrictions initially prevented the firm from filing the report. Apple later contacted the researchers and investigated the flaw.

An official macOS Tahoe 26.6 advisory credits Bynario founder Alfredo Pesoli and two other researchers for CVE-2026-43760. A companion macOS Sonoma 14.8.8 advisory lists the same fix.

Advertisement

High-risk reports need a route around the cap 

A 30-day wait may be too long when a blocked report includes evidence of a high-risk vulnerability. 

Expedited review based on reproducibility and researcher history could help Apple identify credible exceptions without reopening its queue to automated dumping. GitHub, for example, uses researcher track records to set initial bounty access, demonstrating how submission privileges can account for a contributor’s past work.

Researchers blocked by the cap should explain the urgency when requesting additional capacity and preserve a complete disclosure timeline.

Mac administrators do not need an emergency response to the submission policy itself. Fleet owners should confirm current macOS updates are installed, review Screen Sharing and legacy VNC authentication on systems awaiting patches, and avoid delays when applying security fixes.

Also read: Lasso found that changing an AI agent’s harness can produce major differences in red teaming outcomes. 

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.