Apple Caps Bug Bounty Reports as AI Submissions Rise

Apple introduced a cap on open security reports and a 30-day cool-off period in June after a rise in AI-assisted submissions, according to the Financial Times as reported by MacRumors and TechRadar. Researchers who reach the threshold can request a higher quota. Bynar.io said the limit delayed one report, and Apple later credited the firm for CVE-2026-43760 in macOS Tahoe 26.6.
Apple introduced a cap on the number of security reports a researcher can keep open and a 30-day cool-off period in June, according to the Financial Times as reported by MacRumors and TechRadar. Researchers who reach the threshold can request a higher quota. The change was reported in early August; it was not introduced on the date those articles appeared.
Why Apple changed the workflow
The reports describe a rise in submissions produced or amplified with AI tools, including low-quality claims that consume review time without providing a reproducible vulnerability. The operational problem is signal quality: a plausible description is not enough for a security team to reproduce impact, assess exploitability and prioritize a fix.
Apple's public bounty guidelines provide first-party background for that standard. They ask for a precise technical explanation and a working exploit or reliable proof of concept, and they tell researchers to avoid lengthy descriptions generated by AI tools. Apple's terms also identify repeated high-volume spam, ineligible reports and AI-assisted claims that were not validated by a human as prohibited conduct. Those public pages do not disclose the June quota itself.
The Bynar.io example
Bynar.io told reporters that it found more than 50 potential macOS issues in three weeks with ChatGPT assistance and reached Apple's reporting threshold. TechRadar reports that the limit delayed a Screen Sharing Server report involving a legacy VNC configuration.
Apple's July 27 security note for macOS Tahoe 26.6 credits Alfredo Pesoli of Bynar.io and other researchers for CVE-2026-43760, which Apple describes as a Screen Sharing Server access issue addressed with improved restrictions. TechRadar reports that Bynar.io demonstrated root-level file-writing under specified conditions. Apple's public note confirms the CVE credit and fix, but does not itself describe the quota or quantify any reporting delay.
The program-design tradeoff
Rate limits can protect reviewers from noisy submissions, but a flat threshold can also delay a valid report from a productive researcher. Better controls combine reproducibility requirements, duplicate detection, researcher history and a fast escalation path for severe evidence-backed findings.
For teams building AI-assisted vulnerability discovery, the lesson is that discovery volume is not the same as security value. A useful system must produce testable evidence, affected-version details, exploit conditions and a concise impact statement that a human researcher has verified.
Key Points
- 1Apple reportedly introduced an open-report cap and 30-day cool-off period in June, with a process for requesting a higher quota.
- 2Bynar.io said the threshold delayed a report; Apple later credited the firm for CVE-2026-43760 in the July 27 macOS Tahoe 26.6 security update.
- 3Apple's public bounty rules emphasize concise, reproducible, human-validated evidence and reject repeated spam or false AI-assisted claims.
Scoring Rationale
The quota change affects a major vulnerability-disclosure program and illustrates how AI-assisted discovery can create both valid high-severity findings and costly triage noise. Impact is moderated because the numerical open-report cap remains undisclosed.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
