WorkAugust 2, 2026via The Decoder
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Why it matters
AI-generated spam is now operational friction in critical security infrastructure. When bug bounty pipelines clog with fabricated reports, real vulnerabilities slip through — a cautionary tale about AI at scale hitting institutions unprepared for the volume.
Key signals
- Apple's bug bounty program capped submissions per researcher due to AI-generated spam
- Italian startup Bynario initially unable to report serious macOS vulnerability
- Vulnerability worth up to $200,000 on black market
- AI-generated reports clogging review pipeline creates operational bottleneck
- Real security flaw discovery delayed by noise management
- Apple capped bug bounty submissions per researcher due to AI-generated report volume
- AI-generated reports clogging review pipeline
- Real security research delayed by false submissions
The hook
A $200K macOS vulnerability sat unreported because Apple's bug bounty program was buried under AI-generated noise. The company capped submissions per researcher to filter the slop.
Apple's bug bounty program is drowning in AI-generated bug reports. The company has capped submissions per researcher because fabricated reports are clogging the review pipeline. As a result, Italian startup Bynario was initially unable to report a serious macOS vulnerability worth up to $200,000 on…