Apple quietly changed its security report intake in June 2026 to limit how many active vulnerability submissions some researchers can keep open at once, after a wave of AI-assisted reports increased triage pressure and included many claims the company considered low-quality or nonexistent. The company now requires human validation before confirming submissions, allows researchers to request higher limits, and is also using AI internally to help process incoming reports. Apple’s bug bounty rules already warn that repeated ineligible or theoretical AI-generated submissions can trigger a 180-day suspension or permanent removal from the program.
The policy drew attention after Italian security startup Bynario said its Atlas platform, using GPT-5.5, identified more than 50 possible flaws in the latest macOS release within three weeks, but the cap initially prevented it from submitting all findings. Apple and Bynario both acknowledged that at least one report was valid: CVE-2026-43760, a macOS Screen Sharing flaw that could allow an authenticated VNC user to access protected data and create files with root privileges, later fixed in macOS Tahoe 26.6. The dispute has highlighted a broader industry problem as AI speeds up vulnerability discovery faster than vendors and bug bounty platforms can review reports, raising concerns that blunt submission limits could also delay legitimate disclosures.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
AppleInsider reported reproducing the Hide My Email behavior on July 17, 2026, two weeks after Apple’s claimed patch date. The report suggested the issue persisted despite Apple’s statement that it had been fully resolved.
Apple said it deployed a patch for the Hide My Email vulnerability on July 3, 2026, and fully resolved the issue. This followed roughly a year of exchanges after the original report.
In June 2026, Apple changed its security report submission system to limit how many active vulnerability reports a researcher can have open at once. The move followed a surge of AI-assisted submissions, many reportedly low-quality or describing nonexistent issues.
EasyOptOuts co-founder Tyler Murphy reported a vulnerability in Apple’s Hide My Email feature to Apple in June 2025. The bug could expose real email addresses that the feature was intended to protect.
Apple introduced Memory Integrity Enforcement in 2025. Later reporting cited researchers using Anthropic’s Mythos model to identify a bypass of this technology.
Apple fixed CVE-2026-43760 in macOS Tahoe 26.6. The flaw in macOS Screen Sharing could allow an authenticated VNC user to access protected data and create files with root privileges.
After reaching Apple’s new limit for open investigations, Bynario said it was unable to submit all of its macOS findings, including initially one valid issue. Apple later contacted Bynario to review its reports.
Within three weeks in 2026, Italian cybersecurity firm Bynario used ChatGPT/GPT-5.5 via its Atlas platform to identify more than 50 potential vulnerabilities in the latest macOS release. The findings reportedly included a possible privilege-escalation chain and a Screen Sharing issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
bitdefender.com
Open sourcemacrumors.com
Open sourcethenewstack.io
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.