AI/TLDR

Apple · 2026-08-02 · major

Apple caps bug-bounty submissions — AI-slop reports buried a real $200K macOS flaw

The Financial Times reports Apple added a per-researcher submission cap and 30-day cool-off on its Feedback Assistant bug-bounty channel after a flood of AI-generated reports blocked Italy-based Bynario from reporting a real macOS flaw.

Neon green Apple logo illustrating a bug-bounty overload story
The Decoder

Apple's bug-bounty inbox filled up with AI-generated 'flaws,' so Apple capped submissions — and then a real macOS root exploit couldn't get through.

Quick facts

Reported byFinancial Times, 2026-08-02
Channel affectedApple Feedback Assistant bug-bounty submissions
New rulePer-researcher submission cap + 30-day cool-off period
Case in pointBynario (Italy) blocked from reporting a Screen Sharing / VNC macOS flaw
CVE assignedCVE-2026-43760 (fixed in macOS Tahoe 26.6)
Estimated market value$100,000–$200,000 on the grey market (Bynario CEO)
Apple's own AI useApple uses Anthropic and OpenAI models to find bugs; latest update shipped 5x more fixes than usual

What is it?

Apple has quietly added a per-researcher submission cap and a 30-day cool-off period on its Feedback Assistant bug-bounty channel, according to a Financial Times investigation reported on August 2. The change is Apple's response to a rising tide of AI-written vulnerability reports that hallucinate flaws and swallow reviewer time.

How does it work?

Apple's Feedback Assistant tool is the official pipeline for security researchers to send potential vulnerabilities. Under the new rules, a single reporter who trips the cap has to wait 30 days (or request a quota bump) before filing again. The problem: the same rate-limit doesn't distinguish between an AI-generated fake report and a Bynario-caliber engineer with a real root exploit — as shown by CVE-2026-43760 sitting unreported until Apple was tapped on the shoulder.

Why does it matter?

Apple's bug bounty is one of the industry's flagship coordinated-disclosure programs. If AI-generated reports can effectively DDoS the intake channel, other vendors will hit the same wall — and 'AI slop' becomes a real vulnerability class of its own. Meanwhile, Apple itself is running Anthropic and OpenAI models internally to hunt bugs (its latest updates shipped five times more fixes than usual), so the incentive to keep the channel open is asymmetric.

Who is it for?

iOS/macOS security researchers, bug-bounty program owners, vulnerability-disclosure policy people.

Frequently asked questions

What exactly is Apple's new bug-bounty submission cap?
Apple's Feedback Assistant tool now limits how many reports a single security researcher can file, and adds a 30-day cool-off period once the cap is hit. Researchers can request a higher quota, but the default rate-limit is meant to slow the deluge of AI-generated 'vulnerability' reports Apple staff spent months triaging.
Why did Apple introduce the cap now?
According to the Financial Times, Apple's bug-bounty inbox is being overwhelmed by low-quality AI-generated reports with hallucinated flaws. The cap is Apple's attempt to protect reviewer time, but the same cap also blocks legitimate researchers — Italian startup Bynario says it could not file a real macOS Screen Sharing / VNC exploit until Apple was contacted directly.
How serious was the macOS bug that got blocked?
Bynario found a Screen Sharing / VNC authentication weakness that could be built into a working exploit granting root-level command execution. Apple has since assigned CVE-2026-43760, shipped a fix in macOS Tahoe 26.6, and reached out to Bynario. CEO Alfredo Pesoli estimates the flaw's grey-market value at $100,000 to $200,000.
What should security researchers do about the new cap?
Serious researchers can still contact Apple to request a higher submission quota, and the Apple Security Bounty terms describe an escalation path for high-severity findings. For AI-assisted reporting, expect Apple to keep tightening filters and ask reporters to attach reproducible proofs-of-concept rather than model-generated write-ups.

Try it

If you've hit the Feedback Assistant cap on a real bug, request a higher quota via Apple Security Bounty rather than resubmitting through the same choke point.

Sources · 3 outlets

Tags

  • security
  • apple
  • bug-bounty
  • vulnerability-disclosure
  • ai-slop
  • macos
  • feedback-assistant
  • bynario
  • cve-2026-43760
  • ai-safety
  • ecosystem

← All releases · Learn AI