cd /news/artificial-intelligence/apple-s-ai-spam-filter-blocked-a-rea… · home topics artificial-intelligence article
[ARTICLE · art-86743] src=startupfortune.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Apple's AI Spam Filter Blocked a Real $200,000 macOS Security Flaw

Apple's AI-driven spam filter blocked a legitimate $200,000 macOS security exploit discovered by Italian startup Bynario, which used OpenAI's GPT-5.5 to find the critical privilege-escalation bug CVE-2026-43760 in macOS Screen Sharing. Apple's submission portal, capped in June 2026 to curb AI-generated junk reports, rejected Bynario's submission because the company had already filed five reports this year, prompting CEO Alfredo Pesoli to go public; Apple patched the flaw in macOS Tahoe 26.6 after the story broke. The incident highlights the tension between volume-based filters and legitimate fast researchers, as Apple also raised its top bounty to over $5 million and introduced 'target flags' to verify exploitability.

read4 min views1 publishedAug 4, 2026
Apple's AI Spam Filter Blocked a Real $200,000 macOS Security Flaw
Image: Startupfortune (auto-discovered)

Apple capped bug bounty submissions to fight AI-generated spam, and the filter caught a real $200,000 macOS exploit instead.

Bynario is a seven-person security startup in Italy. It used OpenAI's GPT-5.5 to hunt for vulnerabilities in macOS, and in three weeks this summer, the company says its Atlas platform surfaced more than 50 real flaws. One stood out: a critical privilege-escalation bug in macOS Screen Sharing, later catalogued as CVE-2026-43760, that let anyone with VNC access read protected files and run commands with root privileges. Bynario's CEO, Alfredo Pesoli, put its black-market value at $100,000 to $200,000.

Apple's own submission portal wouldn't take it.

According to a report from the Financial Times, the reason is a flood of AI-generated junk. Large language models now let researchers with little technical skill churn out vulnerability reports that look plausible on the page and fall apart under review. Apple's security engineers were drowning in submissions that read like real findings but described bugs that didn't exist. So in June 2026, Apple quietly capped how many reports a researcher can file through its portal in a given window, added a 30-day cool-off once that cap is hit, and gave itself the power to a repeat offender's account for 180 days if they keep filing unvalidated, AI-written reports without human review behind them.

Bynario had already filed five reports this year. That was enough to trip the new limit. When Pesoli tried to submit CVE-2026-43760, there was no channel open to him. Rather than sit on a critical root-level exploit through a 30-day cool-off, he went public. Apple reached out only after the story broke, and patched the flaw in macOS Tahoe 26.6.

A filter that can't tell speed from spam #

Apple's answer isn't just a cap. The company has also deployed its own internal AI system to triage incoming reports before they reach a human reviewer, filtering out submissions that look like hallucinated technical jargon before someone has to read them line by line. It's an odd kind of arms race: language models write the reports, and now a language model reads them first. The trouble, as Bynario's case shows, is that a volume-based filter can't tell a researcher spamming the queue from a researcher who happens to be fast and right. Both look the same at 50 submissions in three weeks.

Apple didn't come away empty-handed here. It raised its top bounty payout past $5 million for the most severe exploit chains, and it introduced what it calls "target flags," a verification step that forces researchers to prove a claimed vulnerability actually reaches a protected part of the system rather than staying theoretical. That's aimed at a real problem: not every plausible-sounding bug report describes something that can actually be exploited.

Every bounty programme is hitting the same wall #

Apple isn't alone in this. GitHub is rethinking its own bounty payouts to make mass AI-driven hunting less profitable, and the cURL project temporarily shut down its rewards programme entirely after a similar wave of bogus AI-generated reports overwhelmed its maintainers. Security bounty programmes across the industry are running into the same math: the cost of generating a plausible vulnerability report has collapsed, and the cost of reviewing one hasn't caught up.

Frankly, the Bynario episode is the clearest evidence yet of where this goes if triage doesn't keep pace. A tool like GPT-5.5 can now find real, chainable, root-level bugs in production software faster than a company as well-resourced as Apple can process the reports about them. That's not a hypothetical about AI's double edge. It's $200,000 worth of exploit sitting in a queue because the filter built to stop spam couldn't tell it apart from spam.

Pesoli says Bynario plans to keep reporting to Apple under the new rules. But the episode leaves an uncomfortable question for every security team running a bounty programme right now. If the researchers using AI well look identical, on paper, to the ones abusing it, what exactly is the cap protecting?

Also read: Mastercard Completes $1.8 Billion Stablecoin Deal With BVNKMeta Stock Swung From a 10% Plunge to a 6% Rally in Four Trading DaysINC Ransomware Exploits Maximum Severity SonicWall SMA1000 Flaws

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @apple 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/apple-s-ai-spam-filt…] indexed:0 read:4min 2026-08-04 ·