Finance.Biggo
Apple Limits Vulnerability Submissions Due to AI-Generated Reports
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Apple has implemented restrictions on vulnerability report submissions due to a surge in AI-generated reports that often contain fabricated security risks. Starting in June, the company capped the number of reports a researcher can submit at one time and instituted a 30-day waiting period between submissions. This decision was prompted by the overwhelming volume of low-quality reports, many generated by users leveraging AI tools like ChatGPT. Italian startup Bynario reported discovering over 50 vulnerabilities in the Mac operating system using AI, including a critical privilege escalation flaw. However, Bynario was unable to report these vulnerabilities due to Apple's new submission limits. Apple has since contacted Bynario to review the submissions. The company continues to manually verify each report while using AI to help categorize the increased volume of submissions. Researchers can request higher submission limits for critical vulnerabilities. The situation highlights the dual-edged nature of AI in cybersecurity, improving discovery while complicating validation.
Key Points: • Apple has restricted vulnerability submissions due to a rise in AI-generated fake reports. • Bynario discovered over 50 vulnerabilities in macOS using AI but faced submission limits. • Apple's new policy includes a 30-day waiting period for additional submissions.