News

Public · Published

NEW: Apple has capped bug bounty submissions after getting flooded with AI-generated "slop" reports, making it harder for researchers to flag real vulnerabilities, per FT.

Apple limited the number of bug bounty submissions it will accept after being overwhelmed by a large volume of low‑quality, AI‑generated reports, which makes it harder for researchers to submit genuine vulnerability findings.

Published:

Updated:

What happened

Apple limited the number of bug bounty submissions it will accept after being overwhelmed by a large volume of low‑quality, AI‑generated reports, which makes it harder for researchers to submit genuine vulnerability findings.

Confirmed

Global impact / market context

Fewer real vulnerability reports could delay fixing security flaws, increasing risk to users and possibly leading to higher costs for Apple if breaches occur, while also affecting the reputation of its bug bounty program.

Confirmed

Apple’s bug bounty program is a key channel for finding security flaws; changes to its submission rules can affect the flow of vulnerability disclosures and the company’s security posture.

Confirmed

What to watch

  1. Whether Apple will adjust the cap or introduce new filters, influencing the volume and quality of future security reports. Analyst inference
  2. How security researchers respond, potentially shifting to other platforms or changing their reporting strategies. Analyst inference
  3. The impact on Apple’s product security if fewer genuine bugs are reported, affecting consumer trust and potential regulatory scrutiny. Analyst inference

Affected assets

  • FT — Flying Tulip

Evidence