Apple struggles to keep pace with AI ‘bug’ hunters
Unlock the Editor’s Digest for free
Roula Khalaf, Editor of the FT, selects her favourite stories in this weekly newsletter.
Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team, as it faces a deluge of reports from people using AI models to identify alleged risks.
The Cupertino-based tech giant told the FT it had moved in June to limit the high volume of requests it was receiving, with its review system coming under pressure from “AI slop” reports that can hallucinate security risks in its software.
Apple is grappling with an industry-wide phenomenon that has resulted in generative AI software tools transforming the cyber security arms race, with an increase in the detection of real security flaws and a wave of poor-quality submissions from amateur bug hunters using AI, the company said.
The change in Apple’s approach was highlighted by Italian cyber security start-up Bynario, which told the FT it had used OpenAI’s ChatGPT to identify more than 50 bugs in the latest version of the MacBook operating system in just three weeks.
Among them was one of the most serious types of vulnerability, a so-called privilege escalation exploit chain, which could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system.
However, the start-up said it was unable to alert Apple to the vulnerability because the tech giant had limited the number of bug reports it could make.
“It is a very difficult time in the industry,” Bynario chief executive and co-founder Alfredo Pesoli said. “Maintainers and vendors have been flooded by the sheer amount of bugs [being found].”
Apple told the FT that it was now in contact with Bynario and reviewing its submissions.
The company has introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota. Each alleged security breach requires human review to confirm, although Apple is also using AI internally to help triage the massive upsurge.
“With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once,” Apple said in a statement.
Researchers “can easily request an increase to that limit at any time to ensure critical reports reach our security teams,” the company continued.
Bynario, a seven-person start-up founded in Milan last year, develops defensive cyber security software. Three of its other co-founders previously worked at Hacking Team, the Italian surveillance software company whose hacking tools were leaked in a 2015 cyber attack.
In 2025, Bynario reported eight vulnerabilities to Apple, one of which was patched in a software update in November. This year it said it had reported five more, before Apple’s system refused further submissions.
The privilege escalation exploit Bynario was unable to report is the latest example of AI exposing weaknesses in Apple’s security systems, despite the company’s longstanding emphasis on privacy and device security.
Last September Apple announced Memory Integrity Enforcement, a security feature designed to prevent memory corruption attacks, one of the most common ways hackers compromise software. The company described it as “the most significant upgrade to memory safety in the history of consumer operating systems”.
Eight months later, researchers at Palo Alto-based Calif said they had found a way past the new security, having used Anthropic’s Mythos to identify the first memory corruption exploit on the latest software.
Unlike that attack, Bynario’s exploit relied on so-called logic flaws, by manipulating trusted software into carrying out a sequence of otherwise legitimate actions in an unintended order. Pesoli estimated that an exploit of this type could fetch between $100,000 and $200,000 on the cybercriminal black market.
Apple last year introduced a new bug bounty award mechanism that could pay out as much as $5mn for identifying the most serious and sophisticated category of threats to its software.
Apple is also using AI to strengthen its software. In security updates released this week for its operating systems, the company credited tools from Anthropic and OpenAI with helping identify a number of vulnerabilities across its devices.
The updates included around five times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defence in cyber security.
The challenge for all software companies is that AI is having a “dual impact” on bug hunting, making it easier for amateur sleuths to submit speculative reports and for skilled researchers to find dangerous exploits, said Rafe Pilling, director of threat intelligence at cyber security firm Sophos.
“The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed.”
Additional reporting by Stephen Morris in Diablo
