
AI "manufacturing" a flood of vulnerabilities overwhelms the review chain, Apple sets limits to cope with the surge of false reports, and the alarm for cybersecurity costs rings
Apple introduced new restrictions in June due to an overwhelming review process caused by a surge in AI-generated false security vulnerability reports, requiring external researchers to submit a limited number of open reports before applying for a higher quota. This move aims to address the challenge of AI accelerating the discovery of real flaws while also generating a significant amount of noise, highlighting the rising costs of cybersecurity and the complexity of distinguishing between real and false threats
According to Zhitong Finance APP, Apple (AAPL.US) is limiting the number of security vulnerabilities that external researchers can submit at one time, following a surge in AI-generated reports that overwhelmed its review process. This phenomenon highlights the new challenges the software industry faces as artificial intelligence accelerates both cyber defenses and cyber attacks.
The tech giant stated that after its security team was inundated with a large number of so-called AI-generated reports—many of which identified vulnerabilities that do not actually exist—it introduced new restrictions in June. Researchers can now only submit a limited number of open reports before they can apply for a higher quota, while Apple internally uses AI to help prioritize the reports received.
For investors, this change underscores the growing role of AI in the field of cybersecurity. AI is helping researchers discover genuine software defects much faster than before, but it is also generating a large number of inaccurate or low-quality reports. As a result, companies like Apple are facing increased costs and complexity in distinguishing real threats from AI-generated noise.
This issue was brought to light when the Italian cybersecurity startup Bynario disclosed that it used OpenAI's ChatGPT to identify over 50 potential vulnerabilities in the latest version of macOS within three weeks. The company stated that one of the findings was a potentially serious privilege escalation vulnerability that could allow attackers to gain extensive control over Macs. However, Bynario claimed it could not submit more reports temporarily as it had reached Apple's submission limit.
Apple stated that it is currently reviewing Bynario's findings and emphasized that researchers can apply for a higher submission limit to ensure significant vulnerabilities reach its security team.
Apple is increasingly using AI as both a defensive and offensive tool. This week's software update thanked OpenAI and Anthropic's AI models for helping identify several vulnerabilities, and the latest version release includes more security fixes than in previous update cycles.
Security experts indicate that this trend is not limited to Apple alone. AI has greatly increased the number of vulnerabilities that researchers can discover, but it has also made it easier for inexperienced users to overwhelm vulnerability bounty programs with speculative findings. This shifts the industry's challenge from discovering vulnerabilities to quickly validating which vulnerabilities are truly important.
Apple's experience illustrates how generative AI is reshaping cybersecurity. This technology makes it easier to identify genuine software weaknesses but also forces companies to establish new systems to filter out the growing flood of machine-generated alerts before attackers can exploit real vulnerabilities
