Apple Caps Bug Reports: AI-Generated Findings Surge
Summary
Apple is now capping the number of security bug reports it accepts. This change comes as the company deals with a significant increase in "AI slop" security findings. Apple confirmed to The Financial Times that it has introduced a limit and a 30-day cool-off period for submissions. Researchers can request an increased quota. These changes, implemented in June, aim to manage the industry-wide surge in bug reports driven by powerful AI tools. Just weeks ago, Apple accelerated security updates in response to these AI tools, releasing fixes that were originally planned for later updates. The company credited researchers using AI tools from OpenAI, Anthropic, and Z.ai for uncovering several vulnerabilities. For example, Calif.io used Anthropic’s Mythos Preview model to build a macOS kernel memory-corruption exploit in five days. The Financial Times also reported on Bynario, a cybersecurity startup. Apple blocked Bynario's submissions after they reported five bugs this year and eight last year. Following this report, Apple is now reviewing Bynario's findings, including a potential privilege-escalation exploit. The bottom line is that the rise of AI tools is changing how companies like Apple manage their security, impacting how researchers can contribute to system safety.
This is an AI-generated audio summary. Always check the original source for complete reporting.