A real macOS flaw worth $200K went unreported because Apple’s bug bounty inbox was full of AI slop

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane August 2, 2026 1 min read
A real macOS flaw worth $200K went unreported because Apple’s bug bounty inbox was full of AI slop

Apple has temporarily restricted the number of bug reports researchers can submit because its review pipeline is overwhelmed by low-quality, AI-generated entries containing hallucinated vulnerabilities. This administrative clog prevented Italian startup Bynario from reporting a serious macOS flaw that grants attackers full control of a machine. The company’s CEO, Alfredo Pesoli, estimates the unreported vulnerability is worth between $100,000 and $200,000 on the black market. Apple has since contacted Bynario to address the issue directly.

The situation highlights a growing tension where artificial intelligence hinders human security efforts while simultaneously being deployed to find flaws internally. Apple is currently using tools from Anthropic and OpenAI to hunt for vulnerabilities, a strategy that has increased the number of fixes in recent updates by five times. Experts warn that bug bounty programmes may struggle to survive if they cannot filter out machine-generated noise at scale. Rafe Pilling of Sophos noted that these programmes have shifted from finding new issues to validating them at machine speed.

* The restriction was imposed after the inbox flooded with submissions lacking genuine technical merit.
* Internal AI tools at Apple have multiplied the volume of discovered security fixes significantly.
* Industry analysts question whether crowdsourced discovery models can function when automated content dominates the input stream.

Scroll to Top