Apple limits bug bounty programs as it struggles to keep pace with ‘AI slop’ hunters

Apple logo

Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team, as it faces a deluge of reports from people using AI models to identify alleged risks, according to reporting by Tom Wilson in London and Michael Acton in San Francisco for Financial Times.

The Cupertino-based tech giant told the FT it had moved in June to limit the high volume of requests it was receiving, with its review system coming under pressure from “AI slop” reports that can hallucinate security risks in its software.

Apple is grappling with an industry-wide phenomenon in which generative AI tools are transforming the cyber security arms race. This has produced both an increase in the detection of real security flaws and a wave of poor-quality submissions from amateur bug hunters using AI, the company said.

The shift in Apple’s approach was highlighted by Italian cyber security start-up Bynario, which told the FT it had used OpenAI’s ChatGPT to identify more than 50 bugs in the latest version of the Mac operating system in just three weeks. Among them was one of the most serious types of vulnerability—a privilege escalation exploit chain that could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system.

“It is a very difficult time in the industry,” said Alfredo Pesoli, Bynario’s CEO and co-founder. “Maintainers and vendors have been flooded by the sheer amount of bugs [being found].”

Apple told the FT that it is now in contact with Bynario and reviewing its submissions. The company has introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to request an increased quota. Each alleged security issue still requires human review to confirm, although Apple is also using AI internally to help triage the surge.

“With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once,” Apple said in a statement. Researchers can request an increase to that limit at any time to ensure critical reports reach its security teams.

MacDailyNews Take: Overwhelmed.



Please help support MacDailyNews — and enjoy subscriber-only articles, comments, chat, and more — by subscribing to our Substack: macdailynews.substack.com. Thank you!

Support MacDailyNews at no extra cost to you by using this link to shop at Amazon.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.