Skip to content

Fake AI Bug Reports Overwhelm Apple, Causing Serious macOS Vulnerability to Slip Through

Fake AI Bug Reports Overwhelm Apple

Apple tried to cut down on the growing number of AI-generated bug reports, but the move ended up delaying the discovery of a serious macOS vulnerability that could be worth up to $200,000 on the black market. It’s another example of how AI is making security research both easier and more complicated at the same time.

Researchers from Bynario said Apple’s revised bug bounty policy slowed the reporting of dozens of vulnerabilities, according to the Financial Times. One of the reported issues was a privilege escalation flaw in macOS Screen Sharing that could allow an authenticated VNC user to read protected files and eventually run commands with root privileges. Apple said it has since contacted Bynario and explained that the policy limiting the number of open reports was introduced after a rise in AI-generated submissions. Researchers who reach the limit must wait 30 days before filing additional reports, though they can request a larger quota through the company’s security portal.

Apple is not the only company struggling with what many in the security industry describe as “AI slop.” The team behind Curl first raised concerns in early 2024, and by 2025 the percentage of bug bounty reports confirmed as genuine vulnerabilities had dropped to under 5%, compared with more than 15% before AI-generated submissions became widespread. The biggest issue is that while AI can produce reports in seconds, people still have to spend time checking whether they’re actually valid.

While AI has contributed to a rise in low-quality bug reports, it has also improved the ability of researchers to identify real vulnerabilities. Bynario’s seven-person team reported eight exploits to Apple last year. After adopting ChatGPT, the researchers discovered more than 50 vulnerabilities in just three weeks. Their attempt to report five of those findings was initially blocked by Apple’s new quota system.

One of the vulnerabilities affected by the reporting delay, identified as CVE-2026-43760, involved a legacy component of macOS Screen Sharing’s VNC password authentication. The older authentication method, retained for compatibility with legacy VNC clients that do not use full macOS credentials, allowed an authenticated VNC user to access protected files beyond their intended permissions. Researchers said the flaw could then be leveraged to execute commands with root privileges. According to Bynario, the exploit did not rely on memory corruption, allowing it to bypass Apple’s Memory Integrity Enforcement, which is designed to detect memory-corruption attacks.

macos
macOS | Image Credit: Apple

Recent software updates highlight the growing impact of AI-assisted vulnerability research. Apple’s security releases in late July patched nearly 200 flaws affecting iPhones, Safari, the App Store, the macOS kernel, and several other products. Google has seen an even sharper increase in Chrome, with its two most recent releases fixing more than 1,000 vulnerabilities combined, exceeding the total addressed across the previous 23 versions. The rapid rise in discoveries has already led Google to shorten Chrome’s release cycle.

The challenge has yet to be fully resolved. AI tools can help small teams identify dozens of real vulnerabilities in a short period, but they can also produce large numbers of unreliable bug reports. Although submission quotas can reduce the workload for security teams, they may also prevent legitimate findings from reaching bug bounty programs.

Maybe you would like other interesting articles there?

Leave a Reply

Your email address will not be published. Required fields are marked *