Apple limits bug reports amid AI-generated spam
🛡️ Apple has imposed tight submission limits and a 30-day cool-off on its bug bounty portal after being overwhelmed by low-quality, AI-generated vulnerability reports that often describe non-existent flaws. These AI submissions can include syntactically valid code and plausible technical explanations, consuming engineer time to triage. The restriction was triggered after a surge of reports from an Italian startup using a GPT-5.5 scanner, which inadvertently locked out a researcher who’d found a critical macOS zero-day. Apple and other platforms like GitHub are evolving processes to filter AI slop while balancing the risk that genuine, valuable reports may be discouraged or diverted to exploit brokers.
