Apple caps bug-bounty submissions as AI slop buries a $200K flaw
Unvalidated AI finds now draw 180-day pauses, while Apple's own Claude- and GPT-powered audit shipped 5x the usual security fixes.

Copy markdown
Two strikes now means a 180-day ban
Apple capped how many reports each researcher can file and will pause anyone who repeatedly submits ineligible, AI-generated findings for 180 days — more than two pauses and you're removed for good. If you use AI to draft or triage security reports, validate every finding yourself before hitting submit; unvalidated slop now costs you access.
A $200K macOS flaw went unreported
Italian startup Bynario found a macOS bug worth an estimated $100K–$200K that could hand an attacker full control of a machine, but couldn't file it because Apple had already blocked further submissions to clear the AI backlog. The real tax of AI slop isn't wasted reviewer hours — it's genuine vulnerabilities that never reach the vendor.
Apple's own AI shipped 5x the fixes
The same automation flooding the inbox is running inside Apple: internal audits using Anthropic and OpenAI models surfaced so many real bugs that recent OS updates carried roughly five times the usual number of security fixes. Patch promptly — those point releases are heavier than they look.
Bug bounties shift from finding to validating
The FT frames the moment as bug hunting moving from discovery toward validating machine-speed findings, raising the question of whether crowd-sourced programs survive when a vendor's own AI out-produces the crowd. For independent researchers, the moat is now credible, reproducible reports — not raw submission volume.