Apple has capped the number of security vulnerability reports individual researchers can submit to its bug bounty program, after AI tools began generating a wave of fabricated bug reports that buried legitimate findings, according to The Financial Times.
The restriction came to light after cybersecurity startup Bynario used ChatGPT to scan macOS for vulnerabilities.
The firm found more than 50 potential bugs within three weeks, including a privilege escalation flaw that could give an attacker unrestricted access to a Mac.
When Bynario tried to report it, Apple’s submission limit blocked them. The company had already filed eight reports in 2025 and five more in 2026 before hitting the ceiling.
Real Bugs Getting Lost
Apple’s review team relies heavily on human analysts to evaluate incoming reports.
As more amateur researchers plug Apple software into AI tools hoping to score bounty payouts, the volume of low-quality and entirely fictional bug reports has climbed sharply. Legitimate submissions are getting delayed or overlooked as a result.
Bynario’s founder described the current environment as a difficult period for the industry, with security teams across the sector struggling to process the sheer number of incoming reports.
Apple has since contacted Bynario directly and confirmed it is reviewing the company’s submissions.
What the Limit Actually Means
Researchers who hit the cap can request an exemption. Apple has said the appeals process exists specifically to prevent critical vulnerabilities from being missed. The company has not disclosed the exact submission threshold.
Apple has also turned to AI on its own side of the process. The company now uses automated tools to help parse and triage incoming reports.
That dual dynamic, AI generating bug reports on one end and AI reviewing them on the other, played out visibly in the recent iOS 26.6 update, which patched nearly 90 security vulnerabilities.
Several of those fixes were credited directly to Anthropic’s Claude and OpenAI’s Codex Security.
The Money at Stake
Apple’s bug bounty program pays up to $2 million for exploit chains tied to real-world attacks.
Researchers who find bugs in beta software or bypasses for Lockdown Mode receive bonus payments that can push total rewards above $5 million per submission.
Those figures have drawn a growing pool of AI-assisted hunters looking for a shortcut to a payout.
For users, the concern is practical. Delays in processing legitimate vulnerability reports mean security flaws can remain unpatched longer.
A researcher sitting on a genuine macOS exploit, unable to file because a submission cap has been reached, represents a gap in the system Apple built specifically to surface those risks faster.