Full Breakdown
Apple Caps AI-Generated Bug Reports Amid Surge of Low-Quality Submissions
8/3/2026, 11:54:14 PM
Core Event
Apple has introduced a limit on how many security reports a single researcher can keep open at once. The change, reported by the Financial Times and echoed by multiple outlets, follows a flood of AI-produced vulnerability submissions that overwhelmed the company’s review team. Researchers who exceed the cap must wait 30 days before submitting additional reports, although urgent or critical findings can trigger a manual expansion of the limit.
Background & Context
Generative AI tools such as OpenAI’s ChatGPT-5.5 and Anthropic’s Claude are now routinely used to scan code and generate potential attack paths. Apple already incorporates these models to discover internal weaknesses, crediting Claude-based research for a recent kernel vulnerability and OpenAI Codex Security for several WebKit issues. The same technology, however, enables external researchers to produce dozens of speculative flaws in seconds, creating a backlog that strains human verification.
Data & Statistics
- Bynario’s Atlas platform, powered by GPT-5.5, identified more than 50 possible macOS vulnerabilities within three weeks, including a privilege-escalation chain in macOS Screen Sharing.
- The Screen Sharing flaw (assigned CVE-2026-43760) was patched in macOS Tahoe 26.6 and could allow an authenticated Virtual Network Computing (VNC) viewer to create files with root privileges when Screen Sharing or Remote Management and legacy VNC passwords are enabled.
- Market estimates value the exploit at $100,000 – $200,000 on the black market.
- Apple’s bug-bounty program now tops out at over $5 million for the most severe exploit chains and uses “Target Flags” to require demonstrable access to protected system areas.
Official Statements & Responses
The company emphasized that researchers can request an expansion of their limit for urgent or critical issues and that human verification remains essential because AI-generated findings may include false positives or unrealistic attack paths.
Verbatim Quotes
- “We've adjusted the number of new reports a researcher can submit at one time due to an industry-wide increase in AI-assisted security submissions,” — Why Apple
- “The entire industry is in a very difficult period,” — Alfredo Pesoli, co-founder and CEO of Bynario
Conflicting Reports & Gaps
Sources agree that Apple’s limits began in June, but no outlet provides a precise rollout schedule or data on how many researchers have been affected. Details on the criteria Apple uses to grant limit expansions remain undisclosed.
What’s Next
Apple has begun employing AI internally to triage incoming reports, prioritising those with concrete proof over speculative submissions. The company’s ongoing adjustments to its bug-bounty program and submission policies will shape how effectively it can balance rapid AI-driven discovery with reliable human verification.
