Apple has decided to impose restrictions on the number of security bug reports that independent researchers can submit to the company. This measure is a response to the overload of the verification system caused by a sharp increase in "low-quality" reports generated using artificial intelligence.

According to The New York Times, the mass use of neural networks to find vulnerabilities has led to a flood of false and incorrect data into the company's security team. While AI has indeed helped identify more real issues, it has also become a tool for hobbyist enthusiasts who began generating huge volumes of reports requiring manual verification.

New rules for researchers

The company explained that limits on the number of new reports a researcher can open simultaneously have been adjusted. This is done to ensure that critical messages reach security specialists and are reviewed on a priority basis. At the same time, developers have left the option to request an increase in the limit at any time.

In addition, Apple has introduced a 30-day waiting period for sending messages through the internal security portal. Despite the use of AI algorithms to sort incoming information, the final check of each bug report still requires human involvement.

Industry reaction and real cases

The new restrictions have already affected the work of cybersecurity professionals. The Italian startup Bynario reported that due to the introduced limits, it could not promptly submit a report on discovered vulnerabilities to Apple. One of them relates to a privilege escalation exploit chain that theoretically allows an attacker to gain full control over the macOS operating system.

Bynario specialists claim that with the help of OpenAI ChatGPT, they managed to identify more than 50 bugs in the latest version of macOS in just three weeks. However, due to the imposed restrictions, this data was not submitted to Apple in full.

The AI paradox: threat and assistance

The situation demonstrates the dual nature of artificial intelligence in the security sector. On the one hand, tools from Anthropic and OpenAI have helped Apple itself improve development efficiency. According to company representatives, thanks to the use of AI, recent software updates contain approximately five times more security fixes than previous releases.

On the other hand, the availability of these same tools to a wide range of users has led to spam in feedback channels. Apple confirmed that it is reviewing the reports submitted by Bynario, trying to find a balance between automating vulnerability detection and the quality of incoming information.