Critical macOS Exploit Left Unreported as Apple Grapples With AI-Generated Bug Report Deluge
Apple's efforts to stem AI-generated security report spam have inadvertently blocked a critical macOS exploit worth up to $200,000 from being reported through official channels.
When AI-Generated Noise Silences Real Security Threats
Apple’s security vulnerability reporting system has hit an unexpected collision: the same artificial intelligence tools enabling genuine security research are now drowning legitimate researchers in bureaucratic constraints. Milan-based Bynario, a cybersecurity startup, discovered this friction the hard way when attempting to report a serious macOS flaw.
Over three weeks, Bynario leveraged ChatGPT to identify more than 50 vulnerabilities affecting the current version of macOS. The research uncovered multiple critical issues, including a particularly dangerous privilege escalation attack chain that could provide attackers with unrestricted access to infected machines. CEO Alfredo Pesoli estimated this single exploit’s value on criminal marketplaces at between $100,000 and $200,000—placing it squarely among the highest-value security findings. Yet Bynario faced an unexpected roadblock: Apple had already suspended acceptance of new vulnerability reports from the firm.
The Policy That Backfired
Apple instituted reporting caps in June following a cascade of fraudulent vulnerability submissions flooding its security portal. The company implemented dual restrictions: a limit on how many concurrent vulnerabilities researchers can report and a mandatory 30-day cooldown period before new submissions could resume. While researchers can petition for expanded quotas, the timing worked against Bynario. By the time the startup had finished validating its findings—including the critical exploit—the submission ceiling had closed.
Apple confirmed it is now engaged with Bynario to review the firm’s research. The company emphasizes that researchers can request higher reporting limits at any time. Internally, Apple has begun using AI tools to sort through the enormous pile of submitted vulnerabilities, distinguishing legitimate findings from false positives.
A Broader Industry Reckoning
The deluge of fabricated vulnerability reports extends well beyond Apple. Security platform Bugcrowd—which works with major clients including OpenAI—observed submissions surge more than four times over during March, with the overwhelming majority being false or low-quality. The situation prompted both HackerOne and Nextcloud to temporarily close their paid vulnerability programs in spring, unable to manage the noise without better filtration.
The underlying incentive structure fuels the problem. During 2025, Meta, Microsoft, Apple, and Crypto.com distributed over $58 million in aggregate bug bounties. Apple alone offers rewards reaching $5 million for individual critical discoveries—creating powerful financial motivation to submit at scale, quality be damned.
The counterintuitive good news: when deployed responsibly, AI research tools excel at finding real security flaws. Apple’s latest round of security patches addressed roughly five times more vulnerabilities than typical cycles, and the company credited both Anthropic and OpenAI tools with identifying genuine exploits. Anthropic’s specialized security model, introduced in March through Project Glasswing and initially restricted to selected researchers, has demonstrated particular promise, with Mozilla reporting it surfaced 271 separate vulnerabilities in Firefox.
Apple’s situation reveals a fundamental tension: machine learning accelerates legitimate vulnerability research, yet simultaneously enables low-effort submissions that erect barriers to reporting critical findings. As AI capabilities mature, the security industry faces an urgent need for better triage systems to distinguish signal from noise without accidentally blocking the next critical discovery.
For the broader tech and crypto ecosystems, this challenge underscores how infrastructure security depends on managing both genuine innovation and malicious noise.
Source: Financial Times, via Decrypt. Not financial advice.