Apple Imposes Bug Report Caps as AI Spam Delays Major macOS Zero-Day Fix
Security caps designed to block AI spam temporarily halted the report of a root exploit valued at $200,000.
Apple Inc. has restricted the number of vulnerability submissions security researchers can file at once, a measure designed to combat a surge in low-quality AI-generated reports that inadvertently delayed the disclosure of a high-severity macOS exploit.
The tech giant instituted a cap on open submissions after being overwhelmed by automated claims, forcing researchers who reach the limit into a 30-day cool-off period unless they request a higher quota through the company’s security portal. Apple confirmed the policy change to the Financial Times after reaching out to cybersecurity firm Bynario, whose researchers were initially blocked from filing critical flaw disclosures.
Among the delayed submissions was a privilege escalation vulnerability in macOS Screen Sharing tracked as CVE-2026-43760. The exploit targets a legacy code path in VNC password authentication used for older clients lacking full macOS credentials. It allows an authenticated VNC viewer to read protected files beyond authorized permissions and escalate to root privileges. Bynario researchers noted the flaw functions without causing memory corruption, bypassing Apple’s Memory Integrity Enforcement system.
The exploit holds a valuation of up to $200,000 on the cybersecurity black market, where zero-day vulnerabilities in major operating systems command premium prices from brokers and threat actors.
The episode underscores how generative AI tools have created a double-edged sword for vulnerability management. Using ChatGPT, Bynario’s seven-person research team discovered more than 50 security flaws in just three weeks, compared to eight disclosures submitted to Apple during all of last year. However, when the firm attempted to file five of the new findings, Apple’s quota system prevented the reports from processing.
While AI enables rapid vulnerability discovery, it has simultaneously flooded bug bounty programs with spurious reports that require intensive human labor to review. Open-source software project Curl reported that its confirmed-vulnerability rate fell below 5 percent, down from more than 15 percent before the influx of AI-generated submissions.
Despite triage bottlenecks, AI-assisted security research has accelerated software patching across the tech industry. Apple’s security update in late July addressed nearly 200 vulnerabilities across iOS, Safari, the App Store, and the macOS kernel. Meanwhile, Google patched more than 1,000 vulnerabilities across its last two Chrome releases—exceeding the total fixed in its previous 23 releases combined—leading Google to speed up its Chrome release cadence.









