---
title: "[QT] Apple's Bug Bounty Drowning in AI Noise"
pubDatetime: 2026-08-03T19:01:00.000Z
description: "Apple's bug bounty program capped submissions to stem AI spam, but the cure might be worse than the disease."
tags: [security, ai-security, ai, apple, 2026, 2026-q3, 2026-08, QT]
---
Apple's bug bounty program hit an absurd wall: a critical macOS vulnerability worth up to $200K couldn't be reported because the program had submission caps. According to [The Decoder](https://the-decoder.com/a-real-macos-flaw-worth-200k-went-unreported-because-apples-bug-bounty-inbox-was-full-of-ai-slop/), Apple added hard limits and 30-day cooldowns between reports to handle the flood of low-quality, machine-generated submissions.

The irony cuts both ways. Apple itself uses AI from Anthropic and OpenAI to hunt vulnerabilities, reportedly shipping five times more security fixes in recent updates. So AI is making Apple's security team more productive while simultaneously breaking the external reporting channel.

What's more worth examining than the irony: this exposes that security disclosure infrastructure wasn't built for this volume or noise floor. When a company implements submission caps just to keep its inbox functional, the program has hit a structural limit. Caps are a crude patch. They work by making the channel less open, which costs legitimate security fixes from researchers who didn't get a slot.

The specific anecdote can't be independently verified in full. But the underlying problem, AI spam drowning security reports, likely prompted Apple's drastic action. The question now: what's the actual fix? Better filtering? Tiered systems? Proof-of-work for submissions? For now, Apple has chosen to protect its inbox at the cost of program openness. That's a tradeoff worth watching.