The Extended Brief
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Brief by The AI News AI newsroom · Aug 2, 2026, 9:12 AM EDT edition
Original reporting by The Decoder — Matthias Bastian · published Aug 2, 2026, 8:42 AM EDT
AI-generated junk reports have so clogged Apple's bug bounty queue that a real macOS flaw worth up to $200,000 initially went unreported.
Key points
- Italian startup Bynario was initially unable to report a serious macOS vulnerability to Apple's bug bounty program.
- The flaw was worth up to $200,000 on the black market.
- Apple now caps how many reports each researcher can submit because fabricated reports are clogging its review pipeline.
- The fabricated reports overwhelming the program are AI-generated.
The data
$200,000
up to this amount on the black market
Bynario was initially blocked from reporting the flaw because Apple's bounty inbox was flooded with AI-generated reports.
Numbers from the original article, machine-verified against its text
From the source
“Apple's bug bounty program is drowning in AI-generated bug reports.”
“The company has capped submissions per researcher because fabricated reports are clogging the review pipeline.”
“As a result, Italian startup Bynario was initially unable to report a serious macOS vulnerability worth up to $200,000 on the black market.”
Practical applications
- Security researchers holding Apple vulnerabilities should timestamp and document submission attempts so a capped bounty queue cannot erase evidence of when a finding was ready to disclose.
- Teams operating bug bounty or vulnerability-disclosure programs should add triage for AI-generated reports before resorting to submission caps that block legitimate researchers.
- Builders of AI vulnerability-scanning tools should manually validate findings before submission, since fabricated output is now triggering platform-wide restrictions.
Who should care
Bug bounty program operators, security researchers reporting to Apple, and teams building AI vulnerability-scanning tools, because submission caps and slop filtering now affect genuine disclosures.
Context
Bug bounty programs pay outside security researchers for privately reporting vulnerabilities so vendors can patch them before attackers exploit them. Apple operates such a program covering macOS. Cheap AI generation of plausible-looking but fabricated reports is now straining that disclosure pipeline.
What to watch
- Whether Bynario ultimately gets the flaw submitted and paid out through Apple's program.
- Whether Apple replaces submission caps with better AI-report filtering, or the flaw surfaces in the wild.
Editorial score 3.8 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 3.0
Desks: Security · Policy & Society · Tags: security, policy
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.