Apple Limits Vulnerability Submissions Due to AI-Generated Reports

Apple Limits Vulnerability Submissions Due to AI-Generated Reports

First seen 2 Aug 2026, 10:48 UTC KucoinFinance.Biggo 82% similarity 51.9

Article Content

Browse articles
ThreatCluster

Apple has implemented restrictions on vulnerability report submissions due to a surge in AI-generated reports that often contain fabricated security risks. Starting in June, the company capped the number of reports a researcher can submit at one time and instituted a 30-day waiting period between submissions. This decision was prompted by the overwhelming volume of low-quality reports, many generated by users leveraging AI tools like ChatGPT. Italian startup Bynario reported discovering over 50 vulnerabilities in the Mac operating system using AI, including a critical privilege escalation flaw. However, Bynario was unable to report these vulnerabilities due to Apple's new submission limits. Apple has since contacted Bynario to review the submissions. The company continues to manually verify each report while using AI to help categorize the increased volume of submissions. Researchers can request higher submission limits for critical vulnerabilities. The situation highlights the dual-edged nature of AI in cybersecurity, improving discovery while complicating validation.

Key Points: • Apple has restricted vulnerability submissions due to a rise in AI-generated fake reports. • Bynario discovered over 50 vulnerabilities in macOS using AI but faced submission limits. • Apple's new policy includes a 30-day waiting period for additional submissions.

ThreatCluster AI How this analysis works

Timeline

2026-06-01
Apple implements submission limits
Apple caps simultaneous vulnerability submissions and introduces a 30-day waiting period due to AI-generated report surge.
Finance.Biggo
2026-08-02
Bynario reports vulnerabilities discovered
Bynario claims to have found over 50 vulnerabilities in macOS, including critical privilege escalation flaws, but could not report them due to limits.
Kucoin
2026-08-02
Apple contacts Bynario
Following the reports, Apple has reached out to Bynario to review the submitted vulnerability information.
Kucoin

Community

Browse all →

Tracked Entities in This Story