SUMMARYApple has capped the number of open bug-bounty submissions researchers can make after being overwhelmed by low-quality and fabricated vulnerability reports generated with AI. Cybersecurity startup Bynario used ChatGPT to identify more than 50 macOS bugs in three weeks and found a privilege escalation issue that could have given an attacker unrestricted access to a Mac. Apple is reviewing Bynario’s submissions and allows researchers to request higher limits for critical findings.

Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction.

Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.