the-decoder.com·3 min read·medium

A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop

M
Matthias Bastian
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
AI Summary

Apple has implemented submission caps on its bug bounty program to combat a surge of low-quality, AI-generated vulnerability reports. This policy change has inadvertently blocked the reporting of a high-value macOS security flaw, sparking debate over the future of crowdsourced vulnerability discovery.

AI as a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit and enforcing a 30-day cooldown period. A flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports . Researchers can request a higher quota.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyaibusiness

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in

A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop — Headlinne — headlinne