Odaily Planet Daily reports that Apple has limited the number of vulnerability reports a single researcher can submit simultaneously, due to an influx of submissions generated by AI that report non-existent flaws. Apple states that researchers can request higher limits at any time, and the company is also using AI internally to triage submissions.
The Milan-based cybersecurity startup Bynario said it used OpenAI’s ChatGPT to discover over 50 vulnerabilities in the latest version of macOS within three weeks, including a privilege escalation chain that could allow attackers to gain full control of Mac devices.
Bynario stated that it could not report the vulnerability because Apple had rejected further submissions. Alfredo Pesoli, CEO of Bynario, estimated the vulnerability’s value on the black market at $100,000 to $200,000; Apple said it had contacted the company and reviewed its work. In June, Apple increased the submission limit and introduced a 30-day cooling period for its Security Bounty program. In recent security updates, Apple listed vulnerabilities discovered with the assistance of Anthropic and OpenAI software, addressing approximately five times the usual number of fixes. (Decryp)
