عاجل
CRYPTO-FRLe Clarity Act sur les cryptomonnaies reporté au Sénat américain avant les vacancesFRGuerre en Ukraine : la progression russe au ralenti face à la résistance ukrainienneFRTour de France femmes 2026 : le peloton s'élance pour l'étape reine au mont VentouxCRYPTO-FRBataille de gouvernance chez Ondo Finance : le géant du RWA au cœur d'une tempête juridiqueFRVerrerie Duralex : trois candidats en lice pour la repriseFR« Restez chez vous » : le FLNC rejette l'autonomie de la Corse et menace les nouveaux arrivantsFRVaste campagne de cyberattaques contre les réseaux d'eau potable américainsFRUne éclipse solaire totale visible en Europe de l'Ouest et en France le 12 aoûtFRMétéo : une nouvelle vague de fortes chaleurs attendue en France dès ce week-endFRAude : un incendie à Montséret après un accident de la routeCRYPTO-FRLe Clarity Act sur les cryptomonnaies reporté au Sénat américain avant les vacancesFRGuerre en Ukraine : la progression russe au ralenti face à la résistance ukrainienneFRTour de France femmes 2026 : le peloton s'élance pour l'étape reine au mont VentouxCRYPTO-FRBataille de gouvernance chez Ondo Finance : le géant du RWA au cœur d'une tempête juridiqueFRVerrerie Duralex : trois candidats en lice pour la repriseFR« Restez chez vous » : le FLNC rejette l'autonomie de la Corse et menace les nouveaux arrivantsFRVaste campagne de cyberattaques contre les réseaux d'eau potable américainsFRUne éclipse solaire totale visible en Europe de l'Ouest et en France le 12 aoûtFRMétéo : une nouvelle vague de fortes chaleurs attendue en France dès ce week-endFRAude : un incendie à Montséret après un accident de la route
Newsgather
رجوعApple Caps Vulnerability Reports Following AI-Generated Bug Submissions Flood
Apple Caps Vulnerability Reports Following AI-Generated Bug Submissions Flood
تقنية
Decryptأول أمستقنية3 د قراءة

Apple Caps Vulnerability Reports Following AI-Generated Bug Submissions Flood

Security teams struggle with hallucinations and high-volume submissions as researchers increasingly turn to AI tools.

نظرة سريعة

Apple limits vulnerability reports per researcher after its security portal is flooded with AI-generated submissions inventing non-existent flaws, temporarily blocking a Milan startup's real exploit chain.

ملخص مُنشأ بالذكاء الاصطناعي

لماذا يهم

Tech companies offer lucrative bug bounty payouts, attracting security researchers who increasingly leverage large language models to uncover vulnerabilities.

حجم الخط

Apple has capped how many vulnerability reports a researcher can file at once, after its security team was swamped by AI-generated submissions that invent flaws that do not exist, the Financial Times reported.

The cap has already cost it a real one. Milan-based cybersecurity startup Bynario told the paper it used OpenAI's ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine.

Bynario could not report it, because Apple had already refused further submissions. Chief executive Alfredo Pesoli put the exploit's value on the criminal market at between $100,000 and $200,000, and said "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple told the FT it is now in contact with the firm and reviewing its work.

Apple moved in June, adding a cap and a 30-day cool-off period on its security portal, with researchers required to apply for a bigger quota. Every alleged flaw still needs a human to confirm it, though Apple is using AI internally to triage the pile. Apple said it had "recently adjusted the number of new reports a researcher can have open at once," and that researchers can ask for a higher limit at any time.

The same tools are working for Apple. In security updates last week, it credited Anthropic and OpenAI software with surfacing flaws, and carried roughly five times the fixes of a normal cycle, according to the FT.

A “submission flood”

The issue of AI bug reporting volume has grown in recent months. In May, security firm Bugcrowd, whose clients include OpenAI, said submissions through its platform more than quadrupled across three weeks in March, and that most were fake. HackerOne and Nextcloud suspended their paid programs in April, with Nextcloud saying no rewards would be paid "regardless of severity" until it found a way to filter the low-effort reports.

The volume is driven by the rewards on offer, with Meta, Microsoft, Apple and Crypto.com paying out at least $58 million between them in 2025, while Apple's own top tier reaches $5 million for a single finding.

At the same time, LLMs are becoming increasingly adept at spotting bugs. In March, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing. Mozilla said it surfaced 271 vulnerabilities in Firefox during internal testing.

In May, Vietnam-based security startup Calif said it had used a preview version to build the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement, the defence Apple announced last September as the biggest memory safety upgrade in the history of consumer operating systems. Calif found the bugs on April 25 and had a working exploit by May 1.

Instead of filing a report, Calif carried the exploit to Apple's California headquarters in person, saying it wanted to avoid "getting buried in the submission flood" that entrants in hacking contest Pwn2Own had been caught in. Bynario tried the portal three months later and could not get in.

AI crypto threats

As well as hunting down threats, AI is also being used to engineer exploits in the crypto space. Coldcard wallet manufacturer Coinkite has suggested that AI was likely used to uncover a bug in its open source firmware that sat unnoticed for five years, enabling attackers to steal more than $100 million from its hardware wallets.

ما الذي يجب مراقبته

توقعات الذكاء الاصطناعي — احتمالات وليست حقائق

  • Bug bounty platforms will implement automated filters to screen AI hallucinations.

    مرجح · خلال أشهر

أسئلة مفتوحة

  • How will Apple verify researchers requesting higher quota limits?
  • What long-term solutions will bug bounty platforms adopt to filter AI hallucinations?

مواضيع ذات صلة

This article was originally published by Decrypt.

أخبار ذات صلة

المزيد حول هذا الموضوعapple