The Extended Brief

A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop

Brief by The AI News AI newsroom · Aug 2, 2026, 9:12 AM EDT edition

Original reporting by The Decoder — Matthias Bastian · published Aug 2, 2026, 8:42 AM EDT

AI-generated junk reports have so clogged Apple's bug bounty queue that a real macOS flaw worth up to $200,000 initially went unreported.

Key points

  • Italian startup Bynario was initially unable to report a serious macOS vulnerability to Apple's bug bounty program.
  • The flaw was worth up to $200,000 on the black market.
  • Apple now caps how many reports each researcher can submit because fabricated reports are clogging its review pipeline.
  • The fabricated reports overwhelming the program are AI-generated.

The data

Unreported macOS vulnerability

$200,000

up to this amount on the black market

Bynario was initially blocked from reporting the flaw because Apple's bounty inbox was flooded with AI-generated reports.

Numbers from the original article, machine-verified against its text

From the source

Apple's bug bounty program is drowning in AI-generated bug reports.

The company has capped submissions per researcher because fabricated reports are clogging the review pipeline.

As a result, Italian startup Bynario was initially unable to report a serious macOS vulnerability worth up to $200,000 on the black market.

Quoted verbatim from the original article at The Decoder by Matthias Bastian

Practical applications

  • Security researchers holding Apple vulnerabilities should timestamp and document submission attempts so a capped bounty queue cannot erase evidence of when a finding was ready to disclose.
  • Teams operating bug bounty or vulnerability-disclosure programs should add triage for AI-generated reports before resorting to submission caps that block legitimate researchers.
  • Builders of AI vulnerability-scanning tools should manually validate findings before submission, since fabricated output is now triggering platform-wide restrictions.

Who should care

Bug bounty program operators, security researchers reporting to Apple, and teams building AI vulnerability-scanning tools, because submission caps and slop filtering now affect genuine disclosures.

Context

Bug bounty programs pay outside security researchers for privately reporting vulnerabilities so vendors can patch them before attackers exploit them. Apple operates such a program covering macOS. Cheap AI generation of plausible-looking but fabricated reports is now straining that disclosure pipeline.

What to watch

  • Whether Bynario ultimately gets the flaw submitted and paid out through Apple's program.
  • Whether Apple replaces submission caps with better AI-report filtering, or the flaw surfaces in the wild.

Editorial score 3.8 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 3.0

Desks: Security · Policy & Society · Tags: security, policy

Evidence basis: Reviewed from the article's full text

This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.