Apple has tightened the rules for its security bug bounty program to stop automated spam from clogging its review pipeline. This change matters because researchers relying on AI tools to scan for flaws now face strict submission limits that could delay critical findings. The company aims to protect its internal triage teams from being overwhelmed by low-quality reports generated by automated scripts.
New quotas target automated vulnerability reports
The new policy introduces a quota cap and a 30-day cool-off period for vulnerability reports submitted through Apple's internal security portal. These restrictions specifically target low-quality security reports that are often produced by AI tools rather than human analysis. Legitimate security researchers retain the ability to request quota increases at any time if their work justifies the exception.
Apple has deployed an internal AI system to triage incoming reports and filter out low-quality submissions before they reach human reviewers. This automated filtering is designed to reduce the volume of noise in the security team's workflow. The system helps distinguish between genuine, high-value findings and the repetitive output of generative models.
The policy shift follows an incident involving Italian cybersecurity startup Bynario, which reported being rate-limited after submitting over 50 macOS vulnerabilities in three weeks using AI. Apple is now in contact with Bynario to review its submissions after the startup identified a privilege escalation exploit chain for macOS. The company pays up to $5 million for severe security threats, while GitHub has adjusted its bounty program to be less generous for low and medium severity bugs.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.