Apple has introduced new submission restrictions on its bug bounty portal following a surge of AI-generated vulnerability reports that threatened to overwhelm the program. The company found that many of these automated submissions were low-quality and described security flaws that did not exist in Apple products, forcing the tech giant to take protective measures.
Bug bounty programs are designed to incentivize security researchers to responsibly disclose vulnerabilities in exchange for financial rewards. Apple's program, which offers payments ranging from thousands to millions of dollars depending on the severity of discovered flaws, has become a target for individuals attempting to use AI tools to generate reports at scale.
The AI-generated submissions presented multiple problems for Apple's security team. Beyond the sheer volume of reports requiring review, many contained fabricated vulnerabilities or misidentified normal system behavior as security issues. This flood of false positives consumed resources that should have been dedicated to evaluating legitimate security research from human experts.
The influx of automated, low-quality reports risks undermining the effectiveness of bug bounty programs across the technology industry. When security teams must spend significant time filtering out AI-generated noise, genuine vulnerabilities may face delayed review and remediation. This creates potential windows of exposure that threat actors could exploit.
Security researchers and organizations participating in bug bounty programs should expect similar restrictions as other companies face comparable challenges. Apple's response signals that the industry will need to develop better verification methods to distinguish between legitimate human research and automated submissions. Researchers should focus on thorough, manual testing and provide detailed, verifiable proof-of-concept demonstrations when submitting vulnerability reports to any bug bounty program.
Source: https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits


