Summary
- Apple has placed restrictions on the number of active bug reports a researcher can submit following an influx of AI-generated entries.
- Bynario claims to have uncovered over 50 macOS vulnerabilities in three weeks, including a chain of exploits that could grant full control of a Mac.
- This week's security updates from Apple included about five times more fixes compared to previous releases.
In response to a flood of AI-generated bug reports that fabricate non-existent vulnerabilities, Apple has imposed a limit on how many reports a researcher can have open simultaneously, as reported by the Financial Times.
The new policy has resulted in the loss of a legitimate exploit. Bynario, a cybersecurity startup based in Milan, revealed to the publication that it utilized OpenAI's ChatGPT to identify over 50 bugs in the latest macOS version within three weeks. Included in these findings was a privilege escalation vulnerability that could allow an attacker complete control over a Mac.
However, Bynario was unable to report this exploit because Apple had already capped submissions. CEO Alfredo Pesoli estimated the exploit's potential market value between $100,000 and $200,000 and noted that "maintainers and vendors have been overwhelmed by the sheer amount of bugs" being reported. Apple has since stated that it is in contact with Bynario to review their findings.
In June, Apple instituted a cap along with a 30-day waiting period for submissions on its security portal, requiring researchers to request an increased limit if needed. Although every reported flaw still necessitates human verification, Apple is leveraging AI internally to manage the influx. The company confirmed it had "recently adjusted the number of new reports a researcher can have open at once," allowing requests for higher limits at any time.
AI tools are proving beneficial for Apple as well. In recent security updates, the company credited software from Anthropic and OpenAI for helping identify flaws, resulting in approximately five times the usual number of fixes, according to the FT.
The “Submission Flood” Challenge
The challenge posed by AI-generated bug reports has intensified over the last few months. In May, Bugcrowd, which services clients like OpenAI, reported that submissions through its platform surged more than fourfold in just three weeks in March, with most being fraudulent. In April, platforms like HackerOne and Nextcloud halted their paid programs, with Nextcloud stating it would not issue rewards "regardless of severity" until it could effectively filter out low-effort reports.
This surge is driven by the substantial rewards available, with companies such as Meta, Microsoft, Apple, and Crypto.com collectively offering over $58 million in 2025, while Apple's top payout for a single finding can reach $5 million.
Simultaneously, large language models (LLMs) are becoming more proficient at detecting vulnerabilities. In March, Anthropic launched Mythos, a model focused on cybersecurity, initially available only to select tech companies, banks, and researchers under Project Glasswing. Mozilla reported that it identified 271 vulnerabilities in Firefox during internal assessments.
In May, the Vietnam-based security firm Calif announced that it had utilized a preview version of an AI model to create the first public macOS kernel memory corruption exploit capable of bypassing Memory Integrity Enforcement, a major security upgrade Apple introduced last September. Calif discovered the vulnerabilities on April 25 and had a functional exploit ready by May 1.
Rather than submit a report, Calif opted to present the exploit in person at Apple's headquarters in California, aiming to avoid getting lost in the submission flood that participants in the Pwn2Own hacking contest had experienced. In contrast, Bynario attempted to use the portal three months later but was unable to submit its findings.
AI and Crypto Vulnerabilities
AI's role extends beyond identifying threats; it is also being utilized to create exploits in the cryptocurrency sector. Coinkite, the manufacturer of Coldcard wallets, has suggested that AI may have been employed to discover a bug in its open-source firmware that remained undetected for five years, allowing attackers to steal over $100 million from its hardware wallets.
This development follows the recent disclosure by Zcash that researcher Taylor Hornby, collaborating with Claude Opus 4.8, found two lines of code in its Orchard shielded pool that enabled undetectable counterfeiting of ZEC for four years. This prompted Zcash to implement the Ironwood upgrade last month to rectify the vulnerability.
