A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Apple's bug bounty program is drowning in AI-generated bug reports. The company has capped submissions per researcher because fabricated reports are clogging the review pipeline. As a result, Italian startup Bynario was initially unable to report a serious macOS vulnerability worth up to $200,000 on the black market. The article A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop appeared first on The Decoder .
Follow The Decoder to make it a durable For You signal.
Apple has capped the number of bug reports individual researchers can submit and introduced a 30-day cooldown after a surge of low-quality, reportedly AI-generated submissions overwhelmed its review process, according to the Financial Times. The limits initially prevented Italian startup Bynario from reporting a serious macOS vulnerability it says could allow full machine takeover; CEO Alfredo Pesoli estimated its black-market value at $100,000–$200,000. Apple has since contacted Bynario, and researchers can request higher quotas. The episode highlights a potential trade-off in using AI for vulnerability discovery: fabricated reports can burden bug-bounty programs and delay reporting of legitimate flaws. Apple is also reportedly using Anthropic and OpenAI systems to find vulnerabilities, while recent updates contained unusually high numbers of fixes, raising questions about how bug discovery and validation will be divided between AI systems, companies, and independent researchers.