With the proliferation of generative AI and large language models (LLMs), the threshold for discovering software vulnerabilities has plummeted. However, this has also unleashed unforeseen repercussions for the cybersecurity divisions of major technological behemoths. To combat the overwhelming deluge of “AI slop,” Apple recently confirmed the implementation of more stringent submission constraints on its renowned Bug Bounty Program.
According to a report by the Financial Times, Apple’s internal security review team is confronting unprecedented pressure. Although artificial intelligence undeniably assists security researchers in autonomously scanning code for anomalies, it concurrently empowers amateur vulnerability hunters to mass-produce reports that appear professional but are riddled with technical flaws or entirely nonexistent “hallucinations.”
Because human security experts must ultimately verify every submission manually, this avalanche of low-quality AI-generated garbage severely paralyzes Apple’s review procedures. Furthermore, it threatens to submerge genuinely critical vulnerability disclosures within a vast ocean of trivial correspondence.
Instituting Submission Caps and a 30-Day Cooling-Off Period
To curtail this chaos, Apple quietly introduced novel regulations to its internal security reporting portal in June. The company established a strict ceiling on the number of open reports permitted for any individual researcher. Upon reaching this threshold, the account enters a mandatory 30-day cooling-off period, during which the submission of new reports is prohibited.
Apple addressed this by stating that if researchers are genuinely convinced they have unearthed a severely threatening vulnerability, they may submit a special request to elevate their reporting quota. This mechanism ensures that critical disclosures successfully reach the security team.
Collateral Damage: High-Value Vulnerabilities Blocked
Nevertheless, these newfound restrictions carry the unintended consequence of collateral damage. Bynario, an Italian cybersecurity startup, recently leveraged a ChatGPT-based platform to unearth more than 50 potential vulnerabilities within macOS in a mere three weeks.
However, when Bynario attempted to report an exceedingly perilous, authentic vulnerability capable of granting an attacker supreme privileges over a Mac system – a flaw with an estimated black-market value of $100,000 to $200,000 – Apple’s system blocked the submission due to the exhausted quota. Fortunately, following media exposure of the incident, Apple proactively contacted the enterprise and initiated remediation of the flaw.
Concluding Perspectives on the AI Security Paradigm
“Fighting magic with magic” appears to be the reluctant reality of the contemporary cybersecurity landscape. Apple is not alone in this endeavor. Google and GitHub have also progressively overhauled their vulnerability reward mechanisms this year, attempting to concentrate resources on intricate logic flaws that evade simplistic artificial intelligence detection.
Intriguingly, while accelerating the remediation of these vulnerabilities, Apple itself heavily relies upon AI models from OpenAI and Anthropic to assist in identifying system defects. This escalating battle of spear and shield, catalyzed entirely by artificial intelligence, has evidently only just begun.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.