AI news story
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Apple's bug bounty program is drowning in AI-generated bug reports. The company has capped submissions per researcher because fabricated reports are clogging the review pipeline. As a result, Italian startup Bynario was initially unable to report a s
Editor's take
A critical macOS vulnerability, potentially worth $200,000, remained undiscovered by Apple's security team due to an influx of AI-generated submissions overwhelming their bug bounty inbox.
This situation highlights a growing problem for major tech companies: the weaponization of generative AI against security programs. The sheer volume of low-quality, automated reports not only diverts human reviewer attention but can actively obscure genuine threats, as demonstrated by Bynario's experience. This impacts the effectiveness of bug bounty programs, which are vital for identifying and mitigating real-world exploits before they are discovered by malicious actors.
Moving forward, it will be crucial to observe how Apple and other organizations adapt their submission and triage processes. The development of AI-powered detection tools for distinguishing human-authored from AI-generated reports, or a shift towards more stringent pre-screening mechanisms, will be key to restoring the efficacy of these vital security initiatives.
Signal score: 3
This event was corroborated by 41 independent sources. The signal score weighs cross-source corroboration, recency, source weight and topic salience. How we rank stories.
Original reporting
This story summarises reporting published by The Decoder. Read the original article at The Decoder.