Overview
- Apple introduced a limit on how many open security reports a researcher can have and a 30-day cool-off on its internal portal to manage a recent surge of AI-assisted submissions.
- The company says the change, put in place in June 2026, responds to rising volume of convincing but non-reproducible 'AI slop' and allows researchers to request higher quotas for critical findings.
- Milan startup Bynario says it used GPT-5.5 to surface more than 50 potential macOS flaws in three weeks and initially hit Apple’s cap before Apple later contacted the firm to review its reports.
- Apple credited AI tools from vendors such as OpenAI and Anthropic for helping find bugs while continuing to require human reproduction of every submission; one Screen Sharing flaw was assigned CVE-2026-43760 and fixed in macOS Tahoe 26.6.
- The wider industry is testing tiered programs and AI-first triage to filter volume, but experts warn blunt caps can delay valid, high-severity reports and that bounty incentives are driving heavier submission flows.