AI slop blocked a real $200K macOS flaw
3 hours ago
- Apple is capping the number of bug reports and enforcing a 30-day cooldown due to a flood of low-quality, AI-generated reports with hallucinated vulnerabilities.
- Italian startup Bynario used ChatGPT to find a serious macOS flaw worth an estimated $100,000–$200,000 on the black market, but could not report it because Apple blocked further submissions.
- Apple has since contacted Bynario about the vulnerability.
- Apple itself uses AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual.
- The situation raises questions about the long-term viability of bug bounty programs, shifting from finding vulnerabilities to validating them at machine speed.