OBSERVABILITY Signal 432
Apple Limits Bug Bounty Submissions After Flood of AI Slop
Apple imposed a cap on open bug-bounty submissions per researcher after AI-generated reports flooded the program with low-quality and fabricated vulnerabilities.
The cap means legitimate critical vulnerabilities may go unreported until researchers navigate an increase-request process, creating a window where real exploits remain unpatched. This is a concrete signal that AI-assisted vulnerability discovery is scaling faster than vendor triage capacity.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Apple capped the number of open bug-bounty reports a researcher can have simultaneously.
A cybersecurity startup used ChatGPT to find over 50 macOS bugs in three weeks, demonstrating AI's ability to scale vulnerability discovery.
Researchers can request an increase to the cap, but the process introduces friction that could delay reporting of critical exploits.
THE CLUSTER