A bright, sunlit Apple Park campus in Cupertino with hundreds of glowing digital bug report icons floating above the circular building, representing the flood of AI-generated vulnerability submissions overwhelming Apple's security team.
News

Apple Is Drowning in AI-Generated Bug Reports

AI-powered security researchers are finding bugs faster than Apple can review them. The company has capped submissions, raised bounties to $2 million, and deployed its own AI to triage the flood.

AppleAI SecurityBug BountyVulnerabilityCybersecurity

Apple has quietly capped the number of vulnerability reports a single researcher can submit at one time, after AI-assisted bug hunters flooded the company’s security review system with more findings than its engineers can verify.

The policy surfaced after Italian cybersecurity startup Bynario reported using ChatGPT to identify more than 50 potential vulnerabilities in macOS in just three weeks — including a privilege escalation exploit chain serious enough to allow full system compromise. Bynario hit Apple’s submission ceiling before it could report every finding. Apple later confirmed it is reviewing the company’s submissions.

🔍 THE BOTTOM LINE

AI has supercharged both sides of the security equation. Researchers can now find bugs at machine speed, but Apple’s human review pipeline can’t keep up — and a meaningful share of AI-generated reports describe vulnerabilities that don’t actually exist. The result is a bottleneck that is reshaping how the world’s most valuable company handles security disclosures.

What Changed

According to the Financial Times, Apple introduced the submission limit in June 2026 without a public announcement. Researchers now face a cap on the number of active security reports they can have open simultaneously. Apple says researchers can request higher limits, but every reported vulnerability must pass human review before confirmation.

The change was prompted by a surge in AI-assisted submissions, many of which described security issues that turned out to be hallucinations — convincing-sounding but ultimately nonexistent. Apple has also begun using AI internally to triage incoming reports before its security engineers review them, creating a system where AI screens AI-generated findings.

The company raised its top bug bounty payout to $2 million and introduced new triage systems to manage the volume. Its previous maximum was $5 million for the most sophisticated discoveries under the expanded Security Bounty program.

A Record Patch Release

The flood of AI-assisted findings is already showing up in Apple’s patch output. In late July, Apple shipped one of its largest-ever security updates, patching 87 vulnerabilities in iOS and iPadOS 26.6, roughly 155 in macOS, and approximately 100 each across watchOS, tvOS, and visionOS. The official release notes credited AI tools — including Anthropic’s Claude and OpenAI’s Codex — as contributors to the discovery process.

Apple’s internal use of AI for vulnerability discovery is reportedly part of an initiative called Project Glasswing, which explores using AI models to surface security flaws before bad actors can exploit them. Security researchers outside Apple are deploying the same class of tools to accelerate their own bug hunting, and the record patch count likely reflects both internal and external AI-augmented research converging at once.

This builds on a pattern we have tracked across the industry. OpenAI’s Codex tool found 11,000 bugs in its first month, and the broader patching crisis now spans 10,000+ Mythos vulnerabilities as AI-accelerated discovery outpaces the industry’s ability to ship fixes.

The Hallucination Problem

The same generative AI that helps researchers find real bugs also produces confident, detailed reports about vulnerabilities that do not exist. A model can describe a privilege escalation chain with plausible function names, realistic attack vectors, and specific memory addresses — all fabricated. For Apple’s security team, each hallucinated report still requires investigation before it can be dismissed.

Earlier this year, security researchers used Anthropic’s Mythos model to identify a bypass for Apple’s Memory Integrity Enforcement technology, a major security protection introduced in 2025. That finding was real. The challenge for Apple — and every platform operator facing the same flood — is separating the real from the hallucinated fast enough to keep pace with the incoming volume.

Apple says every submission still requires human validation regardless of how it was discovered. The company confirmed that AI tools have been credited in official release notes because they contributed to the discovery process, not because they replaced human review.

The Industry-Wide Bottleneck

Apple’s submission cap is a symptom of a structural shift across the security industry. AI-assisted tooling has lowered the barrier to finding potential vulnerabilities, meaning more researchers — and more automated systems — are generating more reports than ever before. Platform operators with finite security teams now face a volume problem that traditional disclosure processes were not designed to handle.

The bottleneck has implications beyond Apple. Every major platform — Google, Microsoft, Meta, Amazon — operates similar bug bounty and disclosure programs. If AI-assisted submissions flood those programs at the same rate, the industry faces a collective triage crisis where real critical vulnerabilities risk being buried under noise.

NZ Angle

New Zealand’s own cybersecurity community is not insulated from this shift. NZ-based security researchers participating in Apple’s bounty program — or any major platform’s program — will face the same submission caps. The broader pattern of AI-accelerated vulnerability discovery also increases pressure on NZ organisations to patch faster, as the window between a bug being found and a working exploit appearing in the wild continues to shrink. For a country with a relatively small cybersecurity workforce, the mismatch between AI-speed discovery and human-speed remediation is especially acute.

❓ FAQ

Can researchers still submit bugs to Apple? Yes. Apple says researchers can request higher submission limits if needed, and every report is still reviewed by Apple’s security team. The cap is on the number of simultaneously open reports, not on total submissions over time.

Are AI-found bugs less reliable than human-found ones? Not necessarily. AI tools have identified real, serious vulnerabilities — including privilege escalation chains and bypasses for memory protections. The problem is that AI also generates hallucinated reports that describe nonexistent vulnerabilities, and distinguishing between the two requires human investigation.

What is Project Glasswing? Apple’s reported internal initiative to use AI models for vulnerability discovery. The company has not officially detailed the program, but its security release notes now credit AI tools including Claude and Codex as contributors.

Does this affect regular Apple users? Indirectly, yes. If Apple’s review pipeline slows down, real vulnerabilities may take longer to patch. On the other hand, AI-assisted discovery means more bugs are being found in the first place — so the net effect on security depends on whether the patching side can keep pace.

🔍 THE BOTTOM LINE

Apple’s quiet submission cap is the first visible crack in a system that was built for human-speed research facing machine-speed discovery. The company is deploying AI to fight the flood AI created — using models to triage reports that models generated. Whether that equilibrium holds will determine how quickly the industry’s most critical vulnerabilities get fixed, and whether the AI security arms race produces safer software or just more noise.

📰 Sources

Sources: Financial Times, Crypto Briefing, iThinkDifferent, Renascence