A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Ad
Skip to content
The Decoder
AI, Menschen, Wirtschaft
-->
Sign In
Register
Subscribe Now
The Decoder
Opens discord in a new tab<br>Opens LinkedIn in a new tab
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Matthias Bastian
View the LinkedIn Profile of Matthias Bastian
Aug 2, 2026
AI as a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit and enforcing a 30-day cooldown period. A flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports. Researchers can request a higher quota.
The cap creates real security gaps: Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could give attackers full control over a machine but couldn't report it because Apple had blocked further submissions. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. Apple has since reached out to Bynario.
Meanwhile, Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual. That raises the question whether bug bounty programs can survive long-term or whether big tech companies will handle vulnerability discovery on their own. Rafe Pilling of Sophos told the FT that bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed."Ad<br>DEC_D_Incontent-1
Ad
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
Subscribe now
Source: Financial Times
Ask about this article…
Search
Top<br>Stories
OpenAI announces its "next major model" Astra by dropping ten previously unsolved math solutions
Thinking Machines bets on efficiency over size with its second model, Inkling Small
AI keeps cracking unsolved math problems, and mathematicians have mixed feelings
Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet
Deepmind dismantles its AlphaFold team as key authors leave for Anthropic
Don't Miss<br>What Matters
Stay in the loop on AI. Clear, useful, no fluff.
Your email address
Subscribe to our Newsletter
Most<br>Popular
Landmark German ruling declares Google's AI Overviews are Google's own words and makes it liable for false answers
Open-source tool pxpipe hides text in PNGs to cut Claude Code and Fable 5 token costs up to 70%
Sam Altman says a whole generation of researchers held AI back by underestimating what scaling could do
For $1.3 million a month, OpenClaw founder Peter Steinberger runs 100 AI agents that code, review PRs, and find bugs
Google launches a tiny board that runs Gemma 3 locally
Fields Medalist says ChatGPT 5.5 Pro delivered "PhD-level" math research in under two hours with zero human help
AI Community<br>& Insights
The Decoder
Follow The Decoder for AI news, background stories and expert analyses.
Opens LinkedIn in a new tab
Opens Discord in a new tab
BETA-TEST
×
Start new search
×
Send
wpDiscuz
Insert
BETA-TEST
×
Start new search
×
Send
wpDiscuz
Insert