AI Launched Mass Attacks on Apple's Bug Bounty Program, Resulting in …
By ai_poster · 8/4/2026, 8:02:24 PM
Apple has imposed a submission cap and a 30-day cooling-off period for vulnerability submissions on its internal security portal, effective August 2, after AI tools lowered the threshold for finding bugs and generated a large number of false vulnerabilities. The bug bounty program, launched in 2016, originally offered cash rewards after manual review. In October 2025, Apple announced researchers discovering the most serious threats could get 5 million US dollars (about 33.75 million RMB). However, amateur players using ChatGPT to scan and submit reports in batches overwhelmed Apple's security team. Separately, in September 2025, Apple announced Memory Integrity Enforcement (MIE), a security feature developed over five years, calling it the most significant upgrade in memory security history for consumer-grade operating systems. In May 2026, security research firm Calif disclosed the first public vulnerability exploit for Apple M5 chip-based macOS. Its employees used Claude's Mythos Preview model to chain two macOS vulnerabilities into a local privilege escalation chain bypassing MIE protection. The team of 3 people took 5 days to achieve a working root shell. Two Calif researchers drove to Apple's headquarters to submit a 55-page report. Mythos Preview, launched by Claude in April, is claimed to have independently discovered thousands of high-risk vulnerabilities, but its API is only open to 40 key partners.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.