Apple Caps Bug Reports After Surge in Fake AI Security Flaws
Apple is cracking down on how security researchers file bug reports, after getting buried under a wave of junk submissions written by AI.
The company told the Financial Times it quietly updated its internal reporting portal back in June, capping how many open bug reports one researcher can have on the go at a time. Hit the ceiling and you’re stuck with a 30-day cooling-off period before you can file again.
The problem is what people in the industry have started calling ‘AI slop’. These are reports that flag security flaws which straight up don’t exist in the code, but a human still has to sit down and check every single one to confirm that, which obviously eats up a lot of time.
“With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once,” Apple said in a statement.
The company says researchers “can easily request an increase to that limit at any time to ensure critical reports reach our security teams,” so legitimate stuff should still land in front of engineers.
Of course, the new limits have already tripped someone up. Italian cybersecurity startup Bynario used OpenAI’s ChatGPT to dig up more than 50 potential bugs in the newest version of macOS over just three weeks. One of them was a nasty privilege escalation exploit that could hand an attacker full control of a Mac. The catch? Bynario couldn’t actually file it at first, because it had already maxed out its report count.
Apple says it’s now talking to Bynario directly and going through its submissions.
While AI may be what’s clogging the pipes, Apple is also using it to unclog them. The company says it runs AI internally to help sort through incoming reports, and gave credit to models from Anthropic and OpenAI for surfacing real vulnerabilities that got patched in its latest software updates. Now that’s what you call fighting fire with fire.
Want to see more of our stories on Google?
P.S. Want to keep this site truly independent? Support us by buying us a beer, treating us to a coffee, or shopping through Amazon here. Links in this post are affiliate links, so we earn a tiny commission at no charge to you. Thanks for supporting independent Canadian media!
