04 August 2026 · 1 views

AI slop security reports are clogging up Apple's bug bounty program

AI slop security reports are clogging up Apple's bug bounty program

AI is flooding Apple's bug bounty system with flawed iOS and macOS security reports. It's so much of a problem that Apple has limited the number of bugs that can be reported to it.

The rise of artificial intelligence is also considered a security problem, with AI models able to determine issues in software that humans have a very low chance of uncovering. However, it also has the byproduct of creating more work for people in the field.

It's not just from an increase in valid concerns, but also reports that are completely made up and treated as genuine.

Apple had to deal with the increase in software bugs reported to its security team caused by researchers using AI models for analysis. It told the Financial Times that it had to introduce a limit to the sheer number of requests to its review system, because of the use of AI.

That deluge includes a massive amount of so-called "AI slop," in that many reports were being sent in that were really AI hallucinations. The reports seemed real, but didn't really work because AI made them up.

To Apple, the problem is twofold, in that AI is being used by many people in different ways

Legitimate researchers have a force multiplier on their hands when it comes to finding flaws, meaning they can find more and submit them quicker.

At the same time, amateurs are also using AI, but with fewer checks made to the discoveries. Cue many reports being sent off to Apple, with a significant number being unchecked and flawed AI hallucinations.

Limited safety

The problem of having so many reports to process, and Apple's decision to limit submissions, is already becoming a risk to security in its own right. Legitimate bugs are being ignored.

An example of this was from the Italian cybersecurity firm Bynario, which uses ChatGPT for its research. For the last update to macOS, Bynario found more than 50 bugs in the space of just three weeks.

The list included one serious privilege escalation exploit chain, a vulnerability that can provide attackers with complete access to a target Mac.

Unfortunately, Apple's limits got in the way, and Bynario couldn't submit it. Apple told the report that it was in contact with the firm and reviewing its submissions.

Apple's cap is accompanied by a 30-day cool-off period for submissions to its security portal, though researchers are able to request for a higher limit before hitting the cap.

"With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can open at once," Apple said. Researchers can "request an increase to that limit at any time to ensure critical reports reach our security teams."

A numbers game aided and hindered by AI

For Apple, the problem is throughput, in that each report requires a human to validate the threat is real.

While humans are a chief component of the process, Apple is also using AI to try and manage the problem AI has helped create. AI is being used as a triage mechanism to manage the surge of claims, but it still requires a human to sign off on claims.

AI isn't just being used as a triage mechanism for the bug reports. Apple's also using AI to find problems for itself.

Using tools like Claude Mythos under Project Glasswing, Apple and other tech companies are shoring up their own security from AI threats. The same AI has been shown to bypass macOS security in completely new ways.

As a result of the AI threat to security, Apple has been working to cut the amount of time between discovery of an exploit and releasing a patch in a software update.

While Apple is working to make AI less of a problem for security reports, it's something that it will struggle to contain in the short term. For professional security outfits, adapting to the limits will take time, as well as force researchers into double-checking their work for AI hallucinations.

But, as the current bounty system offers a hefty payday to the tune of millions of dollars, it won't stop amateurs from trying their luck with unchecked AI submissions.

You May Also Like