The signal-to-noise ratio at Apple has reached a breaking point. As reported by the Financial Times, the tech giant has been forced to restrict vulnerability reports by introducing a mandatory 30-day "cooling-off" period. This defensive measure is a desperate response to an avalanche of low-quality, AI-generated garbage. Thousands of reports containing hallucinations about non-existent security flaws have effectively paralyzed the company’s analysts. While established researchers can apply for higher quotas, the standard limits now prioritize traffic control over rapid threat detection.

The cost of a bureaucratic logjam

The price of this bottleneck has proven to be quite tangible. Bynario, an Italian startup, discovered a critical macOS vulnerability that allows for full device takeover. Bynario CEO Alfredo Pesoli estimates the black-market value of such an exploit ranges from $100,000 to $200,000.

Ironically, Bynario could not report the discovery through official channels because Apple’s limits blocked them from submitting new entries.

As a result, a major security hole remained unpatched simply because the legal gateway was clogged by amateurs experimenting with ChatGPT.

Strategic context

The situation exposes a paradox in modern security: tools designed to automate bug hunting are, in the hands of hobbyists, blinding the security teams of IT giants. Rafe Pilling of Sophos notes a transformation in the Bug Bounty model: platforms are shifting from discovery hubs into validation engines operating at machine speeds.

Apple actively uses Anthropic and OpenAI models for internal code auditing. The latest system update contained five times more patches than usual. The mass influx of amateur AI reports threatens the viability of external research programs.

The bottom line

The system is drowning in mass-market hallucinations, allowing truly dangerous exploits to slip through. While the company optimizes internal processes with AI, the external research community faces artificial barriers that leave the Apple ecosystem more vulnerable to professional hackers.

Artificial IntelligenceCybersecurityGenerative AIAutomationApple