Apple has introduced submission limits and a 30-day waiting period for some vulnerability reports, following a rise in low-quality AI-generated findings.
The restrictions affect researchers who use Apple’s internal security reporting portal. Apple appears to have taken the step after its teams received a large volume of reports that lacked the quality or evidence needed for a proper investigation.
The changes have sparked concern among security researchers. While the company wants to reduce noise, researchers worry that caps could delay the review of serious flaws.
Apple responds to AI-generated vulnerability reports
AI tools can help researchers identify potential security issues faster. However, they can also generate inaccurate or incomplete findings that require time-consuming human review.
Apple now limits the number of open investigations that a researcher can hold at one time. It has also added a 30-day wait for new submissions through the reporting system.
Researchers can contact Apple and ask for a higher limit when they have a valid reason. Still, the new rules may affect teams that submit several legitimate reports at once.
Apple says humans review every report. The company also uses AI to help prioritise reports during the current surge.
Bynario says it found more than 50 MacBook bugs
Italian cybersecurity company Bynario reportedly first noticed the new restrictions.
According to the Financial Times, the company found more than 50 potential bugs in the latest MacBook operating systems within three weeks with help from ChatGPT.
Bynario said one finding involved a privilege-escalation chain that could give an attacker full control of an affected MacBook. The company said the new report limits initially prevented it from flagging that issue through the usual process.
Apple later contacted Bynario to review its submissions.
The company reported eight vulnerabilities to Apple during 2025 and five more this year before Apple introduced the restrictions.
Researchers worry about slower security fixes
The Apple Security Bounty programme encourages researchers to report vulnerabilities responsibly. However, the recent changes raise questions about whether valid reports could face longer delays.
Security teams often need to separate genuine findings from duplicates, inaccurate claims and reports that lack a reproducible technical impact. AI-generated submissions can increase that workload significantly.
At the same time, delays can create problems if a researcher discovers a high-impact flaw. Apple has faced criticism over response times before. Researchers recently raised concerns about a reported issue in the company’s Hide My Email feature that could expose users’ real email addresses.
Apple must now balance two competing needs. It needs to protect its security teams from a flood of poor-quality reports, while ensuring that credible researchers can quickly report serious vulnerabilities.


0 responses to “Apple Limits Security Bounty Reports as AI Submissions Surge”