cd /news/ai-safety/apple-caps-security-bug-reports-amid… · home topics ai-safety article
[ARTICLE · art-85331] src=9to5mac.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Apple caps security bug reports amid surge in AI-generated findings

Apple has introduced a cap and a 30-day cool-off period on bug bounty submissions through its internal security portal, effective June, to manage an industry-wide surge in AI-generated security reports, as confirmed to The Financial Times. The changes follow Apple's accelerated security updates in iOS 26.5.2 and counterparts, which credited AI tools from OpenAI, Anthropic, Z.ai, and others for uncovering vulnerabilities. Apple is now reviewing findings from Bynario, a seven-person cybersecurity start-up that had submissions blocked after reporting five bugs this year.

read2 min views1 publishedAug 3, 2026
Apple caps security bug reports amid surge in AI-generated findings
Image: 9To5Mac (auto-discovered)

As it grapples with a surge in “AI slop” security reports, Apple has recently made changes to its bug bounty program. Here are the details.

Apple limits number of open vulnerability reports #

Apple has confirmed to The Financial Times that it has “introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota.”

Implemented in June, the changes are intended to address an industry-wide surge in bug reports, driven by increasingly powerful LLMs that can find, chain, and exploit vulnerabilities, leaving review teams struggling to keep pace with the volume of submissions.

Just a few weeks ago, Apple confirmed that it was accelerating security updates in response to these AI tools, releasing fixes in iOS 26.5.2 and its counterparts that had originally been planned for last week’s version 26.6 updates.

In the security notes for all those systems, Apple credited researchers who used AI tools from OpenAI, Anthropic, Z.ai, and others with helping uncover several vulnerabilities.

One of the teams credited in the updates was Calif.io, which said in May that it had used Anthropic’s Mythos Preview model to build a working macOS kernel memory-corruption exploit on M5 silicon in just five days.

The FT’s report comes just days after GitHub introduced a tiered system for its own bug bounty program, aimed at curbing AI slop, while distinguishing submissions from verified security researchers.

In its report, The FT tells the story of Bynario, a seven-person cybersecurity start-up that has been using recent AI tools and models to uncover vulnerabilities, had submissions blocked after reporting five bugs to Apple this year, and eight vulnerabilities last year, “one of which was patched in a software update in November.”

As a result of The FT’s reporting, Apple is now in contact with Bynario and reviewing its findings, including a privilege-escalation exploit chain that could potentially give an attacker full control of a Mac.

In a statement to The FT about the recent changes to its bug bounty program, Apple said:

“With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once. […]”

The company added that researchers “can easily request an increase to that limit at any time to ensure critical reports reach our security teams.”

To read The FT’s full report, follow this link.

Worth checking out on Amazon

Geoffrey Cain – ‘Steve Jobs in Exile’David Pogue – ’Apple: The First 50 Years’MacBook NeoLogitech MX Master 4AirPods Pro 3AirTag (2nd Generation) – 4 PackApple Watch Series 11Wireless CarPlay adapter

*FTC: We use income earning auto affiliate links.* [More.](https://9to5mac.com/about/#affiliate)

[our homepage](http://9to5mac.com/)for all the latest news, and follow 9to5Mac on

[exclusive stories](https://9to5mac.com/feature/exclusive/),

[reviews](https://9to5mac.com/guides/review/),

[how-tos](https://9to5mac.com/guides/how-to/), and

[subscribe to our YouTube channel](https://www.youtube.com/9to5mac)
── more in #ai-safety 4 stories · sorted by recency
── more on @apple 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/apple-caps-security-…] indexed:0 read:2min 2026-08-03 ·