Back Finance.Biggo Apple Cracks Down on AI-Generated Security Reports Flooded With 'Fake Vulnerabilities'
Generative artificial intelligence has emerged as a new tool for discovering cybersecurity vulnerabilities, putting Apple on the front lines of an "AI tsunami." While the use of AI tools like ChatGPT to identify security flaws has increased, the company has moved to restrict report submissions as a wave of low-quality reports—many describing non-existent risks as real—has overwhelmed its review process.
According to the Financial Times and other major outlets on Sunday, Apple significantly lowered submission limits on its internal security reporting system starting in June. The company now caps the number of reports a single researcher can submit at one time and requires a 30-day waiting period before additional submissions.
Apple has long operated a dedicated channel for researchers to report security issues found in its products, including the iPhone and Mac. When a report is confirmed as a genuine flaw, the company patches the software and pays researchers up to $5 million (approximately 70 billion won) depending on severity.
The problem: AI-generated "fake vulnerability" reports. Users with limited technical expertise have increasingly asked ChatGPT potential issues in Apple software, then compiled the responses into report format and submitted them. While AI can identify real vulnerabilities, the technology's tendency to "hallucinate"—describing problems that don't exist as if they do—has compounded the review burden. Apple says its security team must manually verify each submission, creating significant strain.
"We've adjusted the number of new reports a researcher can submit at one time due to an industry-wide increase in AI-assisted security submissions," Apple said. "Researchers who discover additional urgent or critical issues can request an expansion of their submission limit."
Real Flaws Found by AI Blocked by New Limits
The concern is that submission caps could also block legitimate reports of dangerous vulnerabilities. Italian cybersecurity startup Bynario said it used ChatGPT to uncover more than 50 flaws in the latest Mac operating system within three weeks. Among the findings was a privilege escalation vulnerability that could allow hackers to gain administrator access and effectively take control of a computer.
However, Bynario was unable to report these vulnerabilities due to Apple's submission limits. "The entire industry is in a very difficult period," said Alfredo Pesoli, co-founder and CEO of Bynario. "Maintenance teams and software manufacturers are being overwhelmed by an enormous volume of vulnerability reports." Apple has reportedly reached out to Bynario and is reviewing the submitted vulnerability information.
Bynario is a seven-person startup based in Milan, founded last year. Its three co-founders previously worked at Hacking Team, an Italian surveillance software company. The firm reported eight security vulnerabilities to Apple last year, one of which was fixed in a November software update. This year, after submitting five reports, Apple's system rejected further submissions.
AI Reshapes Security Landscape: From 'Finding' to 'Verifying'
AI is fundamentally changing the vulnerability discovery landscape. Apple's recent operating system updates included roughly five times more security fixes than releases. The company has publicly acknowledged that AI tools from OpenAI and Anthropic helped identify some of these flaws.
Security analysts say AI is having a "double-edged" effect on vulnerability discovery. "AI makes it easier for casual users to submit speculative vulnerability reports en masse, but it also makes it easier for professional researchers to find genuinely dangerous flaws," said Rafe Pilling, head of threat intelligence at cybersecurity firm Sophos. "The challenge for bug bounty programs has shifted from 'finding vulnerabilities' to 'verifying, prioritizing, and responding at machine speed.'"
Note: Apple says researchers who discover urgent or critical vulnerabilities can request expanded submission limits.
Meanwhile, Apple is also leveraging AI internally to strengthen security. In September of last year, the company introduced "Memory Integrity Enforcement," widely regarded as the most significant memory security upgrade in consumer operating system history. However, Palo Alto-based security research team Calif used Anthropic's "Mythos" AI tool to bypass this security mechanism and identify the first memory corruption vulnerability in the latest system. CEO Pesoli estimates the privilege escalation vulnerability discovered this time could fetch between $100,000 and $200,000 (approximately 3 billion won) on cybercrime markets.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
