Apple has introduced new limits on its security bug reporting system after a surge in AI-assisted vulnerability submissions overwhelmed its security teams. The move comes as generative AI tools make it easier for researchers—and hobbyists—to discover and report potential software flaws at an unprecedented pace.
Apple Introduces New Reporting Limits
According to reports, Apple recently began limiting the number of security reports that researchers can have open at one time through its Security Research portal. The company also added a 30-day waiting period for some researchers before they can submit additional reports unless they request a higher submission limit.
Apple said the changes are intended to manage a growing volume of AI-generated submissions while ensuring that critical vulnerabilities continue to receive prompt attention. Researchers who need to report more issues can request an increased quota through Apple’s security team.
AI Is Changing Cybersecurity
The rapid rise of AI-powered tools has transformed vulnerability research. Large language models can help security experts analyze code, identify weaknesses, and even generate proof-of-concept exploits much faster than traditional manual methods.
While this has helped uncover legitimate security flaws, it has also produced a flood of low-quality or duplicate reports that require human review before they can be confirmed.
Security experts say the industry is facing a new challenge: separating genuine vulnerabilities from inaccurate or AI-generated reports.
Startup Says It Hit Apple’s Submission Cap
Italian cybersecurity startup Bynario said it discovered more than 50 macOS vulnerabilities with assistance from AI tools, including a serious privilege escalation exploit. However, the company claimed it was temporarily unable to submit all of its findings because it reached Apple’s reporting limit. Apple later confirmed it was working directly with the company to review its submissions.
Apple Encourages High-Quality Reports
Apple’s Security Bounty guidelines emphasize that reports should be clear, reproducible, and supported with technical evidence. The company also advises researchers to avoid lengthy AI-generated descriptions and instead provide concise, actionable information that allows engineers to verify the issue quickly.
Apple’s bug bounty program continues to offer substantial rewards for qualifying vulnerabilities, with payouts reaching $2 million for the most severe exploit chains and potentially exceeding $5 million in certain cases.
Industry-Wide Challenge
Apple is not the only organization facing this problem. Several open-source projects and software vendors have reported that AI-generated vulnerability reports are increasing dramatically, creating additional workload for security teams that must manually verify each submission.
Many cybersecurity professionals believe AI will continue to improve software security by helping researchers discover vulnerabilities faster. At the same time, companies must develop better systems for filtering duplicate, inaccurate, or low-quality reports before they reach human reviewers.
Impact on Apple
For investors watching NASDAQ: AAPL, the changes highlight Apple’s continued focus on strengthening its security infrastructure as AI reshapes cybersecurity. Rather than reducing its commitment to security research, Apple appears to be refining its reporting process to ensure engineers can prioritize the most credible and impactful vulnerability reports.
Conclusion
Apple’s new reporting limits reflect a growing challenge across the technology industry. As AI makes vulnerability discovery faster and more accessible, security teams must balance encouraging responsible disclosure with managing an overwhelming number of submissions. Apple’s updated process aims to maintain the effectiveness of its bug bounty program while ensuring critical security issues receive the attention they require.