
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Quick Answer
A serious macOS vulnerability, valued at $100K-$200K, went unreported due to Apple's bug bounty inbox being overwhelmed with low-quality AI-generated reports.
Quick Take
Italian startup Bynario discovered the flaw using ChatGPT but couldn't submit it, raising concerns about the future of bug bounty programs as Apple shifts to AI for vulnerability detection.
Key Points
- Apple's bug bounty program is overwhelmed by low-quality AI-generated reports.
- Bynario discovered a critical macOS vulnerability but couldn't report it.
- The estimated black-market value of the flaw is between $100K and $200K.
- Apple is using AI from Anthropic and OpenAI for vulnerability detection.
- Bug bounty programs may struggle as companies increasingly rely on AI.
📖 Reader Mode
~1 min readAI is a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit because a flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports.
That creates real security gaps. Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could give attackers full control over a machine but couldn't report it because Apple had blocked further submissions. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. Apple has since reached out to Bynario.
Meanwhile, Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual. That raises the question whether bug bounty programs can survive long-term or whether big tech companies will handle vulnerability discovery on their own. Rafe Pilling of Sophos told the FT that bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed."
— Originally published at the-decoder.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

