AI Slop Broke Apple's $200K Bug Bounty

The Cap that Caught $200K
AI is a cybersecurity risk, just not in the way most people expect. Apple has started capping the number of bug reports security researchers can submit and enforcing a 30-day cooldown period between submissions. The reason isn't a shortage of vulnerabilities. It's a flood of AI-generated reports so bad they're drowning the real ones.
The Financial Times reports that Apple's bug bounty program is overrun with low-quality, AI-fabricated security reports. Hallucinated vulnerabilities. Fake exploits. Reports that look real enough to need human review but are entirely made up. The volume has gotten so high that Apple had to impose submission limits per researcher.
Then the real cost showed up.
The One that Got Away
Italian cybersecurity startup Bynario used ChatGPT to discover a genuine macOS vulnerability -- the kind that gives an attacker full control over a target machine. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. It was a serious finding by any measure.
But Bynario couldn't report it. Apple had already blocked further submissions from the company's account because the cap had been reached.
The irony writes itself. Bynario used an AI tool to find a real vulnerability, but the same kind of AI-generated content -- less competent and infinitely more plentiful -- had already clogged the pipeline so thoroughly that the real discovery couldn't get through. Apple has since reached out to Bynario and is reviewing the vulnerability. But the fact that it slipped through at all is a warning sign about what happens when AI slop meets security infrastructure.

AI vs. AI: Apple Fights Fire with Fire
Apple isn't sitting still. The company is itself using AI models from Anthropic and OpenAI to hunt for vulnerabilities internally. Its latest round of security updates included five times as many fixes as usual -- a signal that the AI-driven discovery pipeline is producing results, at least when the AI is being used by the platform owner rather than by random researchers.
But this creates a strange dynamic. Apple benefits from AI-powered vulnerability discovery when it controls the tools. It gets overwhelmed when the same technology is used by outsiders, even well-intentioned ones. The distinction between AI as a security tool and AI as a security problem depends almost entirely on who is holding the prompt.
The broader question for bug bounties
Rafe Pilling of Sophos told the FT that bug bounty programs have shifted from finding vulnerabilities to validating them "at machine speed." The role of the human researcher is no longer about discovering flaws -- it's about proving that AI-generated findings are real, one by one.
This raises uncomfortable questions about whether traditional bug bounty models can survive. If the ratio of fake to real reports keeps climbing, platforms either spend more on triage or start treating every submission as suspect. Both paths degrade the value proposition for legitimate researchers. And as the Bynario case shows, the hardest-hit may not be the platforms themselves, but the researchers who actually find things worth paying for.
Nuance
The AI-generated report problem is real, but it's not a death sentence for bug bounties. Apple's cap is a blunt instrument, and the company has shown willingness to work around it when contacted directly (as with Bynario). The deeper issue -- that AI makes it trivially cheap to produce security theater at scale -- is one every major platform will need to solve. Better automated triage, reputation-based submission systems, and AI-to-AI verification pipelines are all being explored. But for now, a $200K vulnerability sat in limbo because the inbox was too full of nonsense to see it.
Sources
- The Decoder: A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
- Financial Times (via The Decoder): Apple struggles to keep pace with AI 'bug' hunters
- Firstpost: Apple caps AI-generated security reports after flood of 'Fake Vulnerabilities'
- iPhone in Canada: Apple Caps Bug Reports After Surge in Fake AI Security Flaws
- Tech Edition: AI uncovers Apple security flaws faster than Apple can review them