AI Floods Apple Bug Bounty Program, Review Team Offline
Apple
Anthropic
OpenAI
NVIDIA
Apple has imposed a cooldown period and submission limits on its bug bounty program due to an overwhelming influx of AI-generated vulnerability reports, many of which are false positives. This move comes after AI tools like ChatGPT and Claude significantly lowered the barrier to finding bugs, flooding the review process with noise.
Apple's bug bounty program, established in 2016, has been overwhelmed by a surge in AI-generated vulnerability reports, prompting Apple to temporarily disable the submission portal and impose a 30-day cooldown period on August 2. The program had been upgraded in October 2025 with rewards up to $5 million. However, AI tools like ChatGPT have enabled amateurs to bulk-scan code and submit reports, many of which are hallucinated, flooding the review team. In May 2026, security firm Calif disclosed the first public exploit of Apple's M5 chip macOS, using Claude's Mythos Preview model to chain two vulnerabilities into a local privilege escalation, bypassing Apple's Memory Integrity Enforcement (MIE) security feature. The team had a working root shell in five days and had to personally deliver a 55-page report to Apple's headquarters to be noticed. The CVE registration volume is projected to reach 66,000 in 2026, 46% higher than originally estimated. Industry-wide, maintainers are drowning in AI-generated reports, with Curl founder reporting zero real vulnerabilities out of 20 reports in three weeks. Google, Nextcloud, and GitHub have all taken measures to limit AI-generated submissions. Meanwhile, Apple's security updates are now crediting AI tools for the first time, with its macOS Tahoe 26.6 update fixing 194 vulnerabilities and acknowledging contributions from Anthropic's Claude, OpenAI's Codex Security, NVIDIA's AI Red Team, and Z.ai's GLM model. Apple's accelerated release cadence reflects a judgment that waiting for the next regular update is too risky, but the high-frequency releases themselves may introduce new security variables.
- Abbreviations
- MIE = Memory Integrity Enforcement — Обеспечение целостности памяти
- CVE = Common Vulnerabilities and Exposures — Общие уязвимости и экспозиции
Source: QbitAI 量子位 —
original
