Apple Limits Security Bug Reports After Surge in AI-Generated Submissions

Apple has reportedly introduced new limits on security bug submissions after its review system was flooded with AI-generated vulnerability reports.

According to the Financial Times, the company quietly changed its reporting system in June by limiting the number of active security reports researchers can have open at one time. Apple said the move was intended to help manage a growing wave of AI-assisted submissions, many of which ultimately described security issues that didn’t exist.

The company told the publication that researchers can still request higher submission limits if needed, but every reported vulnerability must first be reviewed by Apple’s security team before it can be confirmed.

Apple AI bug reports

Researchers Are Finding More Bugs With AI

The policy came to light after Italian cybersecurity startup Bynario said it had used ChatGPT to identify more than 50 potential vulnerabilities in the latest version of macOS in just three weeks.

According to the report, one of those findings was a privilege escalation exploit chain, a serious class of vulnerability that could potentially allow an attacker to gain full control of a Mac after exploiting multiple security weaknesses.

Bynario said it wasn’t able to submit every discovery because it had already reached Apple’s reporting limit. Apple later confirmed that it is now reviewing the company’s submissions.

The startup isn’t new to Apple’s security program. It reported multiple vulnerabilities to Apple in both 2025 and 2026, with at least one previous report resulting in a security fix released by the company.

Apple Says Human Review Is Still Required

Although AI can generate vulnerability reports much faster than before, Apple says every submission still requires human validation.

According to the Financial Times, the company has also started using AI internally to help triage incoming reports before security engineers review them.

That creates an interesting balance. AI is helping researchers discover more potential vulnerabilities while simultaneously helping Apple process the growing number of reports being submitted.

The challenge is that generative AI doesn’t only produce legitimate findings. It can also generate convincing but inaccurate reports, sometimes referred to as hallucinations, forcing security teams to spend time verifying issues that ultimately don’t exist.

Apple Is Also Using AI to Improve Security

Apple has increasingly acknowledged AI’s role in its own security efforts. In its latest security updates, the company credited OpenAI and Anthropic tools with helping identify several vulnerabilities across iPhone, iPad, Mac, and other Apple platforms.

Last year Apple also expanded its Security Bounty program, offering rewards of up to $5 million for researchers who discover the company’s most sophisticated security vulnerabilities.

The Financial Times report also points to another recent example of AI-assisted research. Earlier this year, security researchers reportedly used Anthropic’s Mythos model to identify a way around Apple’s Memory Integrity Enforcement technology, one of the major security protections introduced in 2025.

While Apple continues strengthening its platforms against increasingly sophisticated attacks, the volume of AI-assisted vulnerability research appears to be creating new operational challenges for companies responsible for reviewing every submission.

(via The Financial Times)

Newsletter
Never miss an Apple story
One email a day, the news that matters. No spam, unsubscribe anytime.
About the Author

Asma Hussain is an editor at iThinkDifferent, where she covers Apple news, streaming services, mobile gaming, and app reviews, with a particular focus on social media and consumer tech. She writes hands-on guides and app coverage drawn from day-to-day use across iPhone, iPad, and Mac. Outside of writing, she's interested in digital illustration, internet culture, and the small design decisions that shape how people use technology.

Leave a Reply