AI is flooding Apple with fake bug reports, and real $200K macOS exploit got lost in the noise
Security researchers at Bynario recently told the Financial Times that Apple's new bug bounty policy held up its efforts to report dozens of vulnerabilities. Among them was a privilege escalation exploit worth up to $200,000 on the black market. Read Entire Article
Generative AI has become a double-edged sword for security teams, helping uncover and fix vulnerabilities faster while also allowing for easy flooding of inboxes with dubious bug reports. Apple recently changed its bug bounty program due to this issue, which delayed the disclosure of a serious exploit worth up to $200,000 on the black market.
Bynario security researchers informed the Financial Times that Apple's new bug bounty policy held up their efforts to report dozens of vulnerabilities, including a privilege escalation exploit. Apple confirmed to the FT that it has since contacted Bynario and implemented a cap on the number of reports a researcher can have open at once, imposing a 30-day cool-off period if the limit is reached.
Curl's security team had warned about AI-generated bug reports since early 2024, but by 2025, the confirmed-vulnerability rate on Apple's bug bounty program fell below 5%, down from over 15% before the AI-slop wave. While AI has increased the number and quality of legitimate bug reports, enforcing bug-report quotas can backfire, as seen with Bynario's efforts to report five exploits to Apple, which were initially blocked due to the new quota system.
One of the reported exploits, CVE-2026-43760, targeted a legacy code path in macOS Screen Sharing's VNC password authentication, allowing an authenticated VNC viewer to read protected files and execute commands with root privileges. This exploit worked without triggering Apple's Memory Integrity Enforcement system, designed to catch memory-corruption attacks.
Despite the challenges, AI-assisted bug hunting shows promise. Apple's latest security update addressed nearly 200 issues across multiple products, while Google's Chrome security team has fixed over 1,000 vulnerabilities in recent versions, prompting a faster release cadence.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.