Apple Limits Bug Submissions Due to AI-Generated Reports
Apple
OpenAI
Anthropic
Apple has limited the number of bug reports researchers can submit due to a wave of low-quality AI-generated reports with hallucinated vulnerabilities. This has created new cybersecurity risks: an Italian startup found a serious macOS vulnerability but couldn't report it because Apple blocked further submissions.
According to the Financial Times, Apple has limited the number of bug reports that security researchers can submit because a wave of low-quality AI-generated reports with hallucinated vulnerabilities is clogging the review system. This creates new cybersecurity risks: the Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could allow attackers to take full control of a computer, but could not report it because Apple blocked further submissions. CEO Alfredo Pesoli estimates the black-market value at $100,000 to $200,000. Apple is now in contact with Bynario. Meanwhile, Apple itself uses AI from Anthropic and OpenAI for vulnerability hunting; the latest updates contained five times as many fixes as usual. This raises the question of whether bug bounty programs can survive long-term or if companies will cover this market themselves. Rafe Pilling from Sophos told the FT that bug bounty programs have shifted from finding vulnerabilities to a problem of validation 'at machine speed.'
Source: The Decoder (DE) —
original
