A serious macOS vulnerability reportedly went unreported because Appleās bug bounty process was clogged with low-quality AI-generated submissions, The Decoder says, citing the Financial Times. The issue was found by Italian startup Bynario using ChatGPT, but the company could not submit it after Apple limited further reports.
The case shows a less obvious security risk from generative AI. The problem is not only that attackers can use AI to find bugs. It is also that defenders can be overwhelmed by plausible-looking reports that describe hallucinated or low-value vulnerabilities.
Bug bounty programs depend on triage. If automated submissions flood review queues, teams may tighten limits or block researchers, which can accidentally keep valid findings out as well. That creates a gap between discovering a flaw and getting it fixed.
The lesson is operational rather than theoretical. Security teams need better filters for AI-assisted reports, and researchers need submission paths that can distinguish serious evidence from machine-generated noise.