Amateur ChatGPT Hackers Are Clogging Apple’s Bug Reports with Hallucinations

Genuine iOS 26 and macOS exploits are getting lost in a sea of AI-generated junk data
iMac bug report
Text Size
- +

Toggle Dark Mode

Apple has begun placing restrictions on the number of vulnerabilities security researchers are allowed to submit to its bug bounty program following a surge in reports of bugs hallucinated by AI models claiming to identify alleged risks.

According to the Financial Times, Apple’s bug review system has been seeing a rapidly increasing volume of poor-quality reports from amateur bug hunters using AI to locate possible vulnerabilities. In many cases, there is no actual vulnerability, and the faulty claims are causing genuine security threats to be lost in the deluge.

Apple’s bug bounty program offers rewards of as much as $2 million for exploit chains used for sophisticated, real-world attacks, in addition to bonuses that can increase those rewards to over $5 million. Reward totals are boosted for bugs found in betas and for bugs that bypass Lockdown Mode.

This Limited-Time Microsoft Office Deal Gets You Lifetime Access for Just $39

Sick and tired of subscriptions? Get a lifetime license for Microsoft Office Home and Business 2021 at a great price!

The Financial Times learned of the submission limit after cybersecurity firm Bynario, a seven-person startup founded in Milan last year, used ChatGPT to locate more than fifty macOS bugs in just three weeks. Bynario discovered a privilege escalation exploit that could provide attackers with unrestricted access to a Mac. However, the startup was unable to report it because it had hit Apple’s limit on the number of bug reports it could submit. Bynario submitted eight reports to Apple in 2025 (one of which was patched in a software update in November), and another five in 2026 before bumping up against the limit.

Bynario develops defensive cybersecurity software. Three of its co-founders previously were employees of Hacking Team, an Italian surveillance software company that had its own hacking tools leaked in a 2015 cyberattack.

“It is a very difficult time in the industry,” Bynario chief executive and co-founder Alfredo Pesoli said. “Maintainers and vendors have been flooded by the sheer amount of bugs [being found].”

Apple told the Times that it was now in contact with Bynario and reviewing its submissions.

While Apple hasn’t removed the cap on the number of bug submissions a researcher can make, an increase in submissions can be requested from Apple’s security team.

“With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once,” Apple said in a statement.

The use of AI hasn’t been all bad, even though it has quickly overwhelmed the human report checkers. Apple has also used AI to parse the submissions and AI has aided the company in finding a large number of bugs. Apple recently released iOS 26.6, which fixes close to 90 security vulnerabilities, some of which are credited to OpenAI’s Codex Security and Anthropic’s Claude.

As noted by FT, AI is having a “dual impact” on bug hunting, as it makes it easier for amateur sleuths to submit speculative reports, while also making it easier for skilled researchers to find dangerous exploits, said Rafe Pilling, director of threat intelligence at cybersecurity firm Sophos.

“The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed,” he said.

Sponsored
Social Sharing