Apple Caps Open Bug-Bounty Reports After Surge in Unvalidated AI Findings

Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue. Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity […]

Written By
Liz Ticong
Liz Ticong
Aug 5, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue.

Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity for additional or urgent findings.

AI tools can uncover legitimate flaws and generate convincing false alarms at similar speed. A volume-based limit may help reviewers regain control, but credible reports can be delayed alongside the junk.

AI-assisted findings still require proof

AI slop reports can look polished while relying on hallucinated, theoretical, or poorly tested findings. These submissions reach bug-bounty programs without enough evidence for reviewers to reproduce the issue or assess its impact.

Apple’s bounty guidelines require a working exploit or reliable proof of concept, numbered reproduction steps and an explanation of the security impact. Under those rules, the company can pause a researcher’s open reports for 180 days after repeated unvalidated AI submissions. More than two pauses can lead to removal from the program.

AI assistance remains eligible when researchers test and verify the findings. Recent security advisories credit work involving Anthropic’s Claude and OpenAI’s Codex Security, adding to evidence that AI-assisted vulnerability research can produce valid discoveries.

A valid Mac flaw hits the submission cap

Financial Times brought the restrictions to public attention after Milan-based security startup Bynario reached its open-report limit. Its seven-person team said ChatGPT helped identify more than 50 potential macOS issues in three weeks.

One finding involved macOS Screen Sharing and could expose protected data or create files with root privileges when legacy Virtual Network Computing password authentication was enabled, according to the startup. Quota restrictions initially prevented the firm from filing the report. Apple later contacted the researchers and investigated the flaw.

An official macOS Tahoe 26.6 advisory credits Bynario founder Alfredo Pesoli and two other researchers for CVE-2026-43760. A companion macOS Sonoma 14.8.8 advisory lists the same fix.

Advertisement

High-risk reports need a route around the cap 

A 30-day wait may be too long when a blocked report includes evidence of a high-risk vulnerability. 

Expedited review based on reproducibility and researcher history could help Apple identify credible exceptions without reopening its queue to automated dumping. GitHub, for example, uses researcher track records to set initial bounty access, demonstrating how submission privileges can account for a contributor’s past work.

Researchers blocked by the cap should explain the urgency when requesting additional capacity and preserve a complete disclosure timeline.

Mac administrators do not need an emergency response to the submission policy itself. Fleet owners should confirm current macOS updates are installed, review Screen Sharing and legacy VNC authentication on systems awaiting patches, and avoid delays when applying security fixes.

Also read: Lasso found that changing an AI agent’s harness can produce major differences in red teaming outcomes. 

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.