apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • iPhone 18
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

Apple limits bug bounty reports due to AI flood

Milan Jovicic by Milan Jovicic
August 4, 2026 - 02:20 CEST
in Apple News
0
Symbolic image for Apple's bug bounty programme: a drawn shield with a checkmark beside a receding stack of incoming reports

Image: Apfelpatient

WhatsAppFacebookEmail
Threads

Security researchers are now only allowed to submit a limited number of open vulnerability reports to Apple at any one time; after that, a 30-day waiting period applies. The reason is a wave of automatically generated vulnerability reports that the testing teams can no longer keep up with. Apple has confirmed the change – and is thus facing a contradiction in its own security strategy.

Language models now find security vulnerabilities faster than humans can test them. For Apple, this has two opposing consequences: The company prioritizes security updates because attackers use the same tools – and at the same time, it throttles the channel through which researchers report their findings. Our overview of Apple's security updates explains how Apple's update cycle works in general and why installing updates is so important.

Key Facts at a Glance

  • In June, Apple introduced a limit on the number of open vulnerability reports at any one time, along with a 30-day waiting period.
  • Researchers can request an increase in their quota, but they must do so actively.
  • The trigger is an industry-wide wave of AI-generated reports of varying quality.
  • A seven-member security team was blocked, even though one of its earlier reports had led to a patch.
  • GitHub had recently introduced a tiered system for its own program.

What Apple has specifically changed

The change affects the internal security portal through which researchers submit their findings. Apple has limited the number of new reports a user can have open at one time. Once this limit is reached, a 30-day waiting period applies.

Anyone wishing to report more information must request an upgrade. Apple emphasizes that this is possible at any time and is straightforward, ensuring that critical reports continue to reach the security teams.

The rule has been in effect since June. It only became public knowledge now through research by the Financial Times, to which Apple confirmed the change.

Why the flood occurred in the first place

Modern language models can not only detect vulnerabilities, but also chain them together and transform them into functioning attack vectors. What used to require weeks of specialized work can now be accomplished in days.

How far this can go was demonstrated by a security team in May: Using an AI model, they built a working attack on the macOS kernel on M5 hardware within five days. We described the case at the time, when an AI model uncovered new macOS vulnerabilities and Apple reviewed the report.

The downside: Alongside credible findings, countless reports flood inboxes that sound plausible but don't stand up to scrutiny. The term "AI slop" has become established in the industry for this phenomenon. Apple isn't alone in this – GitHub recently switched its bug bounty program to a tiered system that separates vetted researchers from anonymous submissions.

The case that brought the change to light

The new rule was revealed by a seven-person security firm that uses modern AI tools. This year, it reported five vulnerabilities to Apple, compared to eight last year – one of which was patched in November.

Despite this record, further submissions from the team were blocked. Among them was a privilege escalation chain that could have allowed an attacker to gain complete control of a Mac.

Only after the media coverage did Apple contact the company and is now reviewing the findings. This is precisely the problem with quantity limits: they don't differentiate between mass-produced goods and documented work, but simply count the quantity.

How the thread has developed since April

This report is not an isolated event, but rather the provisional endpoint of a development that can be traced over four months.

DateEvent
April 7, 2026Apple launches a joint security project with an AI provider
May 14, 2026An AI model creates a working macOS attack within five days.
June 2026Apple introduces a cap and a 30-day lock-in period – initially unnoticed
June 30, 2026Security updates are being prioritized due to AI-driven attack risks.
July 27, 2026iOS 26.6 closes 78 vulnerabilities; AI tools are mentioned in the acknowledgments.
August 3, 2026The quantity limit will be made public

The connection between the third and fourth lines is noteworthy. Apple introduced throttling and, a few weeks later, brought forward security updates that were actually intended for iOS 26.6 – both in response to the same cause, but with opposing effects.

Deliver faster, accept deliveries slower

Apple is accelerating the rollout of security updates while simultaneously slowing down the acceptance of security reports. Both are understandable on their own. Together, they create a strategy that is becoming more open on the outgoing side and more closed on the incoming side.

Furthermore, there's an imbalance in the selection process. Apple is officially working with an AI provider on vulnerability scanning – while a small team using the same class of tools is being held back by quotas. The difference lies not in the methodology, but in access.

A quantity limit is a crude answer to a quality problem. The tiered model that GitHub has chosen addresses the same flood of reports without hindering productive contributors. Apple's decision to take the simpler approach likely has to do with the effort involved – a rating system for researchers needs to be maintained, a number doesn't.

Nothing changes for you immediately, except for one thing: the frequency of security updates has increased, and updates are now also released outside the usual schedule. Installing them promptly has therefore become more important than it was a year ago.

Where the search for vulnerabilities is headed

The real question behind this announcement is not how many reports a company can process, but rather who will be allowed to submit reports in the future. If access is regulated through quotas and partnerships, security research shifts from an open field to a circle of accredited participants. (Image: Apfelpatient)

  • iPhone and Windows: Apple plans shared clipboard
  • Laura Legros returns to Apple out of retirement
  • iCloud: Former Apple employees retained access
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: CybersecurityiOSiPadOSmacOSTechPatienttvOSvisionOSwatchOS
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

iPhone and Windows: Apple plans shared clipboard

Next Post

AppleCare One in Germany: What's really covered

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has been responsible for all editorial content since 2018 — news, rumors, guides, and product reviews. Apple devices here are not test units on loan for two weeks but everyday tools: from the iPhone through MacBook Pro, MacBook Air, and iMac to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it is published.

Drawn outline of the folded iPhone Ultra with square corners on the hinge side and rounded corners opposite, matching the leaked iPhone Ultra screen protectors

iPhone Ultra: Screen protectors reveal the camera position

August 12, 2026 - 3:58 PM CEST
Glass panel set into the aluminium frame on the back of an iPhone 17 Pro Max in Cosmic Orange, whereas the iPhone 20 glass design is said to wrap the glass around the edges

iPhone 20: Glass design is not supposed to be scrapped after all

August 12, 2026 - 2:50 PM CEST
Jennifer Bailey on stage at an Apple event in front of a projected Apple Card, the Apple Pay chief is leaving the company in October

Apple Pay: Jennifer Bailey is leaving Apple in October

August 12, 2026 - 2:31 PM CEST

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch