Apple Limits Vulnerability Submissions Amid AI-Driven Surge

icon MarsBit
Share
AI summary iconSummary
Apple has restricted vulnerability submissions due to an increase in AI-generated reports, according to vulnerability news. The company now enforces a 30-day cooling period after its security team faced pressure from false claims. Bynario discovered over 50 MacBook OS vulnerabilities using ChatGPT, but Apple’s limits initially blocked the report. Researchers can now request higher quotas for critical issues. Apple confirmed it is collaborating with Bynario and using AI to filter reports. The bounty program offers up to $5 million for top threats, with AI tools identifying five times more vulnerabilities than usual. This move comes amid growing coverage of AI and crypto news.

Huo Xing Cai Jing reports that on August 2, according to the Financial Times, Apple, facing a surge in vulnerability reports due to extensive researcher use of AI models to identify software flaws, restricted the number of vulnerabilities researchers could submit simultaneously and implemented a 30-day cooling-off period in June. Apple stated that some AI-generated reports fabricate security risks, placing undue strain on its review systems. Italian cybersecurity startup Bynario said it used OpenAI’s ChatGPT to discover over 50 vulnerabilities in the latest version of the MacBook operating system within three weeks, including a privilege escalation attack chain that could allow attackers to gain full system control of Apple devices. However, due to Apple’s submission limits, Bynario was temporarily unable to report these vulnerabilities. Apple said it has since contacted Bynario and begun reviewing the submissions. Apple emphasized that every security report still requires manual verification, while internally using AI to categorize the increased volume of reports. Researchers may apply for higher submission limits to ensure critical vulnerabilities reach the security team. Bynario estimates that the privilege escalation vulnerabilities it discovered could be worth $100,000 to $200,000 on the underground cybercrime market. Last year, Apple introduced a new vulnerability bounty program offering up to $5 million for the discovery of the most severe and complex threat categories in its software. This week’s system security update also revealed that tools from Anthropic and OpenAI helped identify multiple device vulnerabilities, with the number of fixes being approximately five times higher than in previous update cycles. Security firm Sophos noted that AI is simultaneously improving the efficiency of discovering real vulnerabilities while generating large volumes of low-quality reports, shifting the primary challenge for bounty programs from “finding vulnerabilities” to rapidly validating, prioritizing, and responding to them.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.