344
Productivity & Workflow355
Automation & Workflow224
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps174
Writing & Content Creation203
Data & Analytics141
Photography & Imaging156
Design & Creative170
Customer Support131
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Apple has capped how many security bug reports researchers can file at once, after many low-quality reports created with AI tools flooded its review system.
In short: Apple has put a cap on how many security bug reports a researcher can submit at once, after AI tools led to a flood of reports.
Apple says it is receiving far more reports of possible security problems in its software than before. Many come from people using generative AI tools like ChatGPT to look for flaws. Apple says a lot of these reports are low quality, sometimes describing problems that are not real, which it called “AI slop.”
A security bug is a mistake in software that could let someone break in, like a weak lock on a door. Each report still needs a human to check if it is real and how serious it is. Apple says the higher volume has put its review system under pressure, so in June it added limits in its security reporting portal.
The cap includes a 30-day cool-off period and it limits how many reports a person can have open at once. Apple says researchers can ask for a higher limit so urgent issues can still reach its security teams. Apple also said it is using AI internally to sort and prioritize the growing pile of reports.
The issue became visible after Italian startup Bynario told the Financial Times it found more than 50 bugs in the latest Mac operating system in three weeks using ChatGPT. Bynario said it could not submit one serious bug because it hit Apple’s new limit, although Apple later told the FT it is now in contact with the company and reviewing its submissions.
More companies may add similar limits as AI makes it easier to generate large numbers of “maybe” reports. The risk is that real and dangerous bugs could get stuck in the queue, unless reporting systems make it easy for trusted researchers to get fast attention.
Source: Financial Times