Apple has been forced to cap security reports for its bug bounty program because it is being swamped by false findings generated by artificial intelligence tools. As a researcher or casual cybersecurity observer, you are seeing a multi-million dollar bounty system falter due to the reckless use of LLMs.
- Apple has imposed a strict limit on bug submissions after a storm of false findings (hallucinations) from AI.
- Startup Bynario found itself blocked after using ChatGPT to identify over 50 bugs in macOS.
- Cupertino itself now relies on AI models like its Claude anthropic to correct gaps, while also fighting researcher spam.
The artificial intelligence factor
When the Financial Times revealed Apple's new ceiling, it became clear that generative LLMs have created a huge problem for the security departments of the tech giants. Any "amateur" researcher can now feed a piece of code into a chatbot and receive dozens of theoretical vulnerability reports. According to the data that has seen the light of day, the vast majority of these reports are non-existent bugs or figments of the algorithm's imagination.
The result? Apple's security people spend their time filtering out noise instead of actually investigating exploits that threaten millions of users. At TechNoid, we've previously covered the rise of automated hacking tools, όμως η μετάβαση από τα scripts στα LLM hallucinations αλλάζει εντελώς τους κανόνες του παιχνιδιού.
The case of Bynario
Το μέγεθος του προβλήματος φάνηκε καθαρά από την εμπειρία της κυβερνοασφαλιστικής startup Bynario, η οποία χρησιμοποίησε το ChatGPT για να εντοπίσει πάνω από 50 bugs στο macOS σε space μόλις τριών εβδομάδων. Ανάμεσα σε αυτά υπήρχε και ένα κρίσιμο exploit τύπου privilege escalation που θα μπορούσε να δώσει σε έναν εισβολέα ανεμπόδιστη πρόσβαση σε οποιοδήποτε Mac.
However, Bynario found itself at a dead end. Having exhausted the limit of eight reports it could send to Apple in 2025 and another five in 2026, the system banned it. While it found a truly dangerous backdoor, it risked being left out of the process because the submission pool was filled with low-quality automated reports from others. Apple is already reviewing their submissions, but the incident proves that the current evaluation model is “broken.”
Apple's dilemma
It's ironic that Apple is fighting AI with its own weapons, but also falling victim to it. The company has one of the most generous bug bounty programs in the industry, offering rewards of up to $2 million for real-world exploit chains, which can exceed $5 million with bonuses.
At the same time, however, Apple itself uses tools like Codex Security OpenAI to identify and fix vulnerabilities, going so far as to patch nearly 90 vulnerabilities in a single update like iOS 26.6. The problem isn't the technology itself, but the fact that Apple itself relies mostly on humans to review the reports it receives externally, creating a huge productivity bottleneck.
Our opinion at TechNoid
We at TechNoid believe that Apple’s cap is nothing more than a temporary safety net, not a solution. Banning or limiting submissions ultimately punishes serious researchers who use smart tools to get their work done faster, while leaving the backdoor open for malicious hackers who don’t care about bounties and will exploit loopholes in the dark. If Apple wants to protect its ecosystem, it should invest in automated AI filtering systems that will separate real exploits from chatbot “delusions,” instead of putting human hackers in charge.
Frequently Asked Questions about Apple's bug bounty and AI hallucinations
Why did Apple put a limit on bug bounty reports?
Apple limited submissions because it was overwhelmed by a huge volume of false reports and low-quality data produced by researchers using artificial intelligence tools.
What are AI hallucinations in security reports?
These are cases where language models (LLMs) "invent" non-existent errors or vulnerabilities in the code, misleading researchers who submit them without prior checks.
Which company faced a problem with Apple's ceiling?
Cybersecurity startup Bynario found itself blocked after it identified over 50 bugs in macOS using ChatGPT and was unable to submit its critical reports.
How much are the rewards in Apple's bug bounty program?
Rewards can reach up to $2 million for complex exploits, and can exceed $5 million with additional bonuses.
Does Apple use artificial intelligence for its security?
Yes, Apple leverages tools like Anthropic's Claude and OpenAI's Codex Security to identify and fix security vulnerabilities in its operating systems.
Can researchers request an increase in the submission limit?
Yes, researchers have the ability to request an increase in the threshold so that Apple's security team does not miss a critical and existing bug.
How does this measure affect individual researchers?
It significantly hinders independent researchers and small startups that rely on automation, as they risk losing the right to report critical bugs.


