
Apple has introduced new limits on software vulnerability submissions after experiencing a massive surge of AI-generated security reports that overwhelmed its cybersecurity review team. The move comes as artificial intelligence continues to reshape the way researchers discover and report software vulnerabilities.
According to reports, Apple’s security team has been dealing with a sharp increase in bug submissions since June. Many of these reports were generated with the help of AI tools, but a large number described vulnerabilities that either could not be reproduced or did not actually exist. As a result, Apple has imposed submission limits for external researchers, with additional reports requiring special approval.
One high-profile example involved Italian cybersecurity startup Bynario, which reportedly used ChatGPT to identify more than 50 potential vulnerabilities in the latest version of macOS within just three weeks. Among them was a critical issue that could potentially allow attackers to gain control of a Mac. However, the company was unable to submit all of its findings after reaching Apple’s reporting limit.

Apple later contacted Bynario to review the reported vulnerabilities and emphasized that researchers can request expanded submission quotas when they discover significant security issues. The company has also begun using AI technologies from OpenAI and Anthropic to help prioritize incoming reports and identify genuine vulnerabilities more efficiently.
Industry experts believe the challenge extends beyond Apple. While AI enables experienced researchers to uncover software flaws much faster than before, it also makes it easier for inexperienced users to generate large volumes of low-quality or speculative vulnerability reports for bug bounty programs.
The situation highlights both the opportunities and challenges artificial intelligence brings to cybersecurity. As AI becomes a powerful tool for vulnerability research, technology companies are increasingly investing in smarter filtering systems to distinguish legitimate security findings from AI-generated noise before critical vulnerabilities are overlooked.
 Origin: Seekingalpha





