Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by a flood of low-quality, AI-generated vulnerability reports, many of which describe security flaws that simply do not exist. The crackdown, while intended to stem the tide of hallucinated submissions, now risks preventing genuine security researchers from reporting critical flaws in time—a paradox that could leave Apple’s software less secure than before.
AI-Generated Bug Reports Overwhelm Apple’s Security Portal
According to a report in the Financial Times, Apple has been facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely fabricated bug reports. Unlike traditional spam, these AI-generated reports include syntactically correct code, references to genuine API calls, and detailed technical explanations of what is supposedly occurring. An Apple engineer might spend hours configuring test environments and attempting to replicate a flaw, only to ultimately verify that it does not exist.
In response, Apple has implemented a cap and a 30-day cool-off period on submissions through its bug-reporting portal. Any user who wishes to submit additional reports must file a special request. The measure was triggered after the Italian cybersecurity startup Bynario developed a custom AI scanning tool built on GPT-5.5, which submitted a burst of more than 50 macOS bug reports within just three weeks. Previously, without AI assistance, Bynario had filed only 13 reports across 2025 and early 2026.
How the AI Slop Crackdown Nearly Missed a Critical Zero-Day
Bynario found that it had automatically triggered Apple’s self-imposed limit and was locked out of the reporting portal just as the team uncovered a critical zero-day flaw in macOS that could give attackers full root control over a computer. Alfredo Pesoli, Bynario’s chief executive and co-founder, told the Financial Times that the exploit could fetch between $100,000 and $200,000 on the computer underground. Apple has since received details of the flaw, but the incident highlights the very real concern that genuine, serious bug reports may be blocked by the very measures designed to filter out poor-quality AI slop.
What Is a Hallucinated Bug Report and Why Does It Matter?
A hallucinated bug report is a vulnerability description that appears technically sound but is entirely fabricated by an AI model. It includes code that compiles, references to real API functions, and credible-sounding explanations of the exploit mechanism. Because the report looks legitimate, a security engineer must invest significant time to investigate and reproduce the issue. When thousands of such reports flood a portal, the cost in wasted engineering hours is enormous. The problem is that the same AI tools that generate these hallucinations are also used by legitimate researchers to automate discovery, making it difficult to distinguish between genuine and fake submissions.
Apple’s Own AI Use Creates a Poignant Irony
Ironically, Apple itself is actively using AI to find vulnerabilities in its code. Its iOS 26.6 and macOS Tahoe 26.6 updates fixed around 100 security flaws, crediting AI models from Anthropic and OpenAI as well as its own internal AI triage tools. The company is simultaneously leveraging AI for security research while building walls against AI-generated noise. This duality underscores the broader industry challenge: how to embrace AI as a tool for good without being buried by its misuse.
GitHub and Other Platforms Face Similar Challenges
Apple is not the only company struggling with a deluge of automated AI-generated vulnerability reports submitted in the hope of receiving generous bounties. GitHub recently introduced a tiered bug bounty system specifically designed to filter out AI slop, by establishing an invite-only VIP group of verified researchers and limiting public submissions. The pattern is emerging across the industry: platforms are forced to restrict access to their bounty programs to maintain quality, but doing so risks alienating the very researchers who discover the most critical flaws.
What Are the Risks of Restricting Bug Bounty Submissions?
Restricting bug bounty submissions carries a significant risk: if reporting security holes becomes too frustrating for vulnerability researchers, they may weigh their options. A third-party exploit broker is likely to offer upfront cash payouts for accepted submissions, with no caps on how many exploits are submitted and no cool-off periods. Worst of all, exploit brokers may have no qualms about selling details of a vulnerability to someone who intends to abuse it. The result is that Apple’s well-intentioned filter could push researchers—and the vulnerabilities they discover—into the hands of less scrupulous actors.
The Economics of Bug Bounties in the Age of AI
Bug bounties have become a cornerstone of modern software security. By offering financial rewards for responsible disclosure, companies incentivize independent researchers to find and report vulnerabilities before malicious actors do. The bounty amounts can be substantial: Apple’s top payouts for critical iOS and macOS flaws can reach $1 million. However, the economics are shifting. AI tools reduce the cost of generating reports, making it economical for researchers to submit hundreds of low-quality reports in the hope that a few will be genuine. This creates a tragedy of the commons: the bounty pool is diluted, engineers are overwhelmed, and the overall signal-to-noise ratio plummets.
How Apple’s 30-Day Cool-Off Period Works
Under the new rules, any user who submits a bug report will be subject to a cap on the number of reports they can file within a 30-day window. Once the cap is reached, the user is locked out of the portal and must submit a special request to Apple to resume reporting. The cap is not publicly disclosed, but Bynario’s experience suggests it is triggered after a burst of around 50 reports. The cool-off period is designed to force submitters to be more selective, but it also punishes researchers who discover multiple distinct vulnerabilities in a short period, as can happen during intensive security audits.
What Can Apple and Other Companies Do to Distinguish AI Slop from Genuine Reports?
Several approaches are being explored. One is to require submitters to complete a verification process, such as proving past successful reports or undergoing a background check. Another is to use AI-powered triage tools that can analyze the semantic coherence of a report and flag potential hallucinations. Apple already uses internal AI triage tools, but they are not yet effective enough to eliminate false positives. A third approach is to create a reputation system, where researchers earn trust over time and gain access to a higher submission limit. GitHub’s invite-only VIP group is an example of this strategy. The challenge is to balance accessibility with quality control, ensuring that new researchers can still enter the ecosystem without being gated out.
When Did Apple Implement the Bug Bounty Caps?
The exact date of implementation is not publicly known, but the Financial Times report indicates that the caps were triggered by the behavior of Bynario’s AI scanning tool, which submitted more than 50 reports in three weeks. This suggests the caps were introduced in early 2026, likely in response to the growing volume of AI-generated submissions seen throughout 2025. Apple has not made an official announcement, but the policy is now encoded in the bug-reporting portal.
The Broader Threat: AI-Generated Vulnerabilities and the Future of Security Research
As AI models become more capable, the quality of hallucinated bug reports will improve. We may soon reach a point where AI-generated reports are indistinguishable from human-written ones, making it nearly impossible to filter them without also blocking legitimate submissions. This could lead to a fundamental redesign of bug bounty programs, moving away from open submissions toward invitation-only or subscription-based models. The risk is that the security community becomes fragmented, with only a small number of vetted researchers having access to the most important bounty programs, while the rest are left to seek alternative channels—including exploit brokers.
Practical Steps for Security Researchers Navigating Apple’s New Limits
Researchers who discover multiple vulnerabilities should prioritize their most critical findings and submit them carefully, avoiding the temptation to batch-submit all at once. They should also consider building a track record with Apple by submitting one or two reports first and requesting verification before filing additional ones. For those who hit the cap, the special request process is available, but it may introduce delays. It is also worth noting that Apple’s bug bounty program is not the only route; researchers can periodically check for updates to the program’s policies, as the company may adjust the cap based on feedback.
What Does This Mean for the Industry’s Security Posture?
The immediate takeaway is that the deluge of AI-generated reports is a systemic problem that demands systemic solutions. No single company can solve it alone. The vulnerability research community, platform operators, and AI developers must collaborate to establish standards for report verification, shared blacklists of known hallucinated patterns, and perhaps even real-time credibility scoring of submitters. Without such coordination, the bounty ecosystem risks being overwhelmed, and the most dangerous vulnerabilities may go unreported to the vendors who can fix them.
For Apple, the stakes are particularly high. The company has built its reputation on security and privacy, and a high-profile zero-day that is sold to an exploit broker rather than reported to Apple could cause significant reputational damage. The Bynario incident serves as a warning: the very tools that are meant to protect the platform can inadvertently create new risks. The path forward requires a careful balance—embracing AI for security while building robust defenses against the noise it generates. The clock is ticking, and the next critical bug might already be locked out of the portal.