律动BlockBeats
律动BlockBeats|8月 02, 2026 05:43
[AI Assistance Leads to Surge in Vulnerability Reports, Apple Limits Submissions by Researchers] BlockBeats News, August 2: According to the *Financial Times*, Apple has restricted the number of vulnerabilities researchers can submit simultaneously and implemented a 30-day cooling-off period as of June, following a surge in reports received by its internal security team due to researchers using AI models to identify software vulnerabilities. Apple stated that some AI-generated reports fabricate security risks, putting pressure on its review system. Italian cybersecurity startup Bynario revealed that it used OpenAI's ChatGPT to discover over 50 vulnerabilities in the latest MacBook operating system within three weeks, including a privilege escalation attack chain that could allow attackers to gain full system control of Apple computers. However, due to Apple's submission limits, the company was temporarily unable to report the vulnerabilities. Apple has since contacted Bynario and begun reviewing the findings. Apple emphasized that each security report still requires manual verification and that the company is also using AI internally to categorize the influx of reports. Researchers can apply to increase their submission limits to ensure critical vulnerabilities reach the security team. Bynario estimated that the privilege escalation vulnerability it discovered could be worth $100,000 to $200,000 on the cybercrime black market. Last year, Apple introduced a new bug bounty program offering rewards of up to $5 million for identifying the most severe and complex threats in its software. In a system security update released this week, Apple disclosed that tools from Anthropic and OpenAI helped identify multiple device vulnerabilities, with the number of fixes in this round being approximately five times that of previous update cycles. Security company Sophos noted that AI is simultaneously improving the efficiency of discovering genuine vulnerabilities while generating a large volume of low-quality reports. The challenge of bug bounty programs is shifting from "finding vulnerabilities" to quickly verifying, prioritizing, and responding to them. [Original Article Link]
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads