Apple is limiting how many security bugs outside researchers can submit at one time after a surge of AI-generated reports overwhelmed its review process, highlighting a new challenge facing the software industry as artificial intelligence accelerates both cyber defense and cyberattacks, the Financial Times reported.
The tech giant said it introduced new limits in June after its security team was inundated with what it described as AI-generated reports that often identified vulnerabilities that did not actually exist.
Researchers can now have only a limited number of open submissions before requesting a higher quota, while Apple uses AI internally to help prioritize incoming reports.
For investors, the change underscores AI’s growing role in cybersecurity. AI is helping researchers uncover legitimate software flaws much faster than before, but it’s also generating large volumes of inaccurate or low-quality reports. The result is rising costs and complexity for companies like Apple (AAPL) as they sort genuine threats from AI-generated noise.
The issue came to light after Italian cybersecurity startup Bynario said it used OpenAI’s ChatGPT to identify more than 50 potential vulnerabilities in the latest version of macOS within three weeks. The company said one of those findings was a potentially serious privilege-escalation exploit that could allow an attacker to gain broad control of a Mac. However, Bynario said it was temporarily unable to submit additional reports because it had reached Apple’s reporting limit.
Apple said it is now reviewing Bynario’s findings and emphasized that researchers can request higher submission limits to ensure significant vulnerabilities reach its security teams.
The company has increasingly embraced AI as both a defensive and offensive tool. This week’s software updates credited AI models from OpenAI and Anthropic with helping identify several vulnerabilities, and the latest releases included significantly more security fixes than previous update cycles.
Security experts say the trend extends well beyond Apple. AI has dramatically increased the number of bugs researchers can discover, but it has also made it easier for less experienced users to flood bug bounty programs with speculative findings. That shifts the industry’s challenge from discovering vulnerabilities to quickly verifying which ones actually matter.
Apple’s experience illustrates how generative AI is reshaping cybersecurity.
The technology is making it easier to uncover genuine software weaknesses, but it’s also forcing companies to build new systems capable of filtering an ever-growing wave of machine-generated alerts before attackers can exploit the real ones.
