The influx of low-quality submissions, which Apple describes as slop, stems from AI tools hallucinating nonexistent security risks. This volume has overwhelmed the company’s triage process, leading to the current quota system. For Bynario, an Italian cybersecurity startup, the policy nearly silenced a discovery that holds significant value. The team identified over 50 bugs in the latest macOS version within three weeks, including the high-stakes flaw that bypassed the initial submission window.
In section CEO World
Apple’s AI-Fueled Bug Report Crisis Risks Real Security Threats
A surge of AI-generated junk reports has forced Apple to cap the number of bug submissions researchers can file, creating a dangerous backlog. The policy backfired when a critical macOS vulnerability that could grant attackers full system control was blocked by the automated limit before security engineers could review it.

Alfredo Pesoli, CEO of Bynario, warned that the industry is currently struggling under the sheer weight of these reports. While Apple has since opened a line of communication to review the startup's findings and noted that researchers can request quota increases, the incident underscores the friction between automated defense mechanisms and legitimate threat hunting. On the black market, the vulnerability uncovered by Bynario could command between $100,000 and $200,000, highlighting the cost of a missed report.
Comments (0)
No comments yet. Be the first!