DevOps / SRE / Platform · 04.08.2026, 16:03 UTC
Apple’s bug bounty limit reveals a problem no one knows how to solve yet
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | DevOps / SRE / Platform |
| Quelle | The New Stack ↗ |
| Veröffentlicht | 04.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-43760. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Apple now caps how many security reports some researchers can have open at once. And once they hit that cap, they may have to wait 30 days before reporting another potentially dangerous software flaw through the company’s internal security portal.
AI slop floods security pipeline
The company introduced the limitations in June after receiving a flood of AI-assisted reports, many of which turned out to be “AI slop,” meaning they were not genuine vulnerabilities. Although AI can help researchers find possible flaws and compile detailed reports, each submission still has to be reproduced and verified.
Italian cybersecurity company Bynario drew attention to the new rules after it reached the limit. According to reporting from the Financial Times, Bynario used GPT-5.5 through its Atlas platform to find more than 50 possible bugs in Apple’s latest Mac operating system in just three weeks.
One of those findings was a flaw in macOS Screen Sharing that could allow an authenticated VNC user to access protected data and create files with root privileges. Apple assigned it CVE-2026-43760 and fixed it in macOS Tahoe 26.6. Bynario said it couldn’t report the flaw at first because it had already hit Apple’s limit for open investigations. Apple has since reached out to Bynario to review its reports.
A human reviews every security issue reported to Apple, even though the company uses AI to help sort reports when there are too many. If researchers hit the cap, they can ask Apple to raise it. But this shows how quickly AI-assisted research can flood a process that relies on people to …