Connect with us

Mobile Tech

Rogue Hackers Flood Apple’s Bug Reports with Fake Claims

Published

on

iMac bug report

Apple has implemented new restrictions on the number of vulnerabilities that security researchers can submit to its bug bounty program due to a rise in reports of AI-generated bugs. These bugs are being identified by AI models, leading to an influx of poor-quality reports that are overwhelming Apple’s bug review system.

The Financial Times reported that amateur bug hunters are using AI to locate potential vulnerabilities, resulting in many false claims of bugs. This surge in inaccurate reports is causing genuine security threats to be overlooked.

Apple’s bug bounty program offers rewards of up to $2 million for exploit chains used in real-world attacks, with bonuses that can increase the total reward to over $5 million. Additional rewards are given for bugs found in betas and those that bypass Lockdown Mode.

The Financial Times discovered the submission limit after cybersecurity firm Bynario, founded in Milan, used ChatGPT to identify over fifty macOS bugs in three weeks. Bynario found a privilege escalation exploit that could grant attackers unrestricted access to a Mac, but they were unable to report it due to reaching Apple’s submission limit.

Bynario, which develops defensive cybersecurity software, had three co-founders who previously worked at Hacking Team, an Italian surveillance software company. Bynario submitted eight reports to Apple in 2025 (one of which was patched in a November update) and five more in 2026 before reaching the submission limit.

Alfredo Pesoli, Bynario’s CEO and co-founder, stated, “It is a very challenging time in the industry as maintainers and vendors are overwhelmed by the sheer volume of bugs being found.”

See also  Enhanced Customization: Apple's New Subtitle Features for iPhone

Apple confirmed that they are reviewing Bynario’s submissions and are now in contact with the company. While the cap on bug submissions remains, researchers can request an increase in submissions from Apple’s security team.

Apple stated, “With the growing number of AI-generated security submissions, we have adjusted the number of new reports a researcher can have open at once.”

AI has had both positive and negative impacts on bug hunting. While it has led to an increase in speculative reports, it has also helped skilled researchers find dangerous exploits. Apple recently released iOS 26.6, addressing nearly 90 security vulnerabilities, some of which were credited to AI technologies.

Rafe Pilling, director of threat intelligence at Sophos, mentioned that AI has changed the landscape of bug bounty programs, shifting the focus from finding vulnerabilities to validating and responding to them quickly.

The use of AI in bug hunting is continuing to evolve, presenting challenges and opportunities for researchers and companies alike.

Trending