Apple Caps Security Bug Reports After Surge in AI-Generated Submissions
*Apple has adjusted its bug bounty program to limit the volume of low-quality, AI-produced security reports it receives.*
Apple made changes to its bug bounty program to address a sharp increase in security findings generated by AI tools. The move comes as the company deals with what it describes as “AI slop” overwhelming its review process.
The adjustments cap the number of reports that can be submitted under certain conditions. This follows a noticeable rise in automated or low-effort submissions that consume reviewer time without yielding actionable vulnerabilities.
Prior state of the program
Before the changes, the program accepted reports without strict volume limits tied to quality signals. Researchers could submit findings as they found them, and Apple paid out for valid issues.
The new rules respond directly to the volume spike. Apple has not released specific submission caps or payout adjustments in the available reporting.
Reactions
No public statements from Apple or independent researchers appear in the source material on the exact thresholds now in place.
Why it matters
Security teams at every large vendor now face the same problem: cheap generation of plausible but shallow reports that still require human triage. Capping submissions is a blunt filter that may reduce noise, yet it also risks slowing legitimate researchers who use AI as one tool among many. The longer-term effect will depend on whether Apple pairs the cap with clearer criteria for what counts as a substantive report.
---
Sources:
No comments yet