Apple bug cap blocked $200K macOS exploit, startup says

Apple limited open bug reports after AI-driven submissions. Milan startup Bynario says the cap prevented it from filing a macOS privilege‑escalation exploit worth $100,000–$200,000.

Apple limited how many vulnerability reports a researcher can have open at once after a surge of AI-generated submissions. Milan cybersecurity startup Bynario says that limit prevented it from submitting a macOS privilege‑escalation exploit chain it discovered using ChatGPT and valued at $100,000–$200,000.

Bynario reports it found more than 50 macOS bugs over three weeks but could not file the highest‑value finding because Apple’s portal refused further reports from the same researcher account.

In June, Apple added a cap on open reports and a 30‑day cool‑off period on its security portal. Researchers can request a larger quota. Apple confirmed it recently adjusted the number of open reports a researcher can have and that researchers may ask for a higher limit at any time. The company said human reviewers still confirm alleged flaws and that it is using AI internally to help triage higher volumes of submissions.

Alfredo Pesoli, Bynario’s chief executive, estimated the exploit’s market value at $100,000–$200,000 and wrote that “maintainers and vendors have been flooded by the sheer amount of bugs.” Apple told Bynario it is reviewing the firm’s findings and is in contact with the startup.

Security teams and open‑source projects have recorded sharp increases in automated or low‑quality bug reports produced with large language models and other AI tools. Many of those submissions require staff time to validate or dismiss, and some programs have temporarily paused or adjusted bounty arrangements while they build better screening.

At the same time, AI tools have been used to surface legitimate vulnerabilities. Apple’s most recent security updates credited software from both Anthropic and OpenAI and contained roughly five times the number of fixes typical for previous cycles.

Other research teams report fast exploit development with advanced models. A Vietnam‑based startup said it used a preview version of Anthropic’s model to develop a macOS kernel memory corruption exploit that bypassed recent M5 protections; the team delivered that exploit to Apple in person to avoid portal delays.

Companies and bounty platforms have paid large sums for high‑severity findings, creating an incentive to automate scanning and bulk reporting. Industry groups and platforms are testing automated filters and new triage methods to separate low‑effort, AI‑generated reports from high‑quality submissions.

Apple’s cap aims to reduce the backlog on its portal while preserving channels for researchers to request higher quotas and for humans to review significant vulnerabilities.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author