Apple has implemented new limits on the number of security vulnerability reports that researchers can submit to its internal review team, citing a surge in AI-generated bug submissions that has strained its capacity to evaluate potential threats. The change, effective since June, reflects the company’s response to a growing influx of reports generated by artificial intelligence tools, which in some cases have produced misleading or low-quality findings.

The technology giant, based in Cupertino, California, told reporters that the volume of incoming security reports, often spawned by generative AI models, has overwhelmed its bug review system. These AI tools have accelerated the pace of vulnerability detection industry-wide but have also contributed to a significant rise in inaccurate or non-critical submissions, complicating the triage process for security experts.

The limits impose a cap on the number of open reports a researcher can maintain simultaneously, accompanied by a 30-day waiting period before submitting additional findings unless a special request for increased quota is approved. This approach aims to prioritize quality over quantity and help maintain manageable workloads for Apple’s security team.

Italian cybersecurity firm Bynario highlighted the impact of the new policy after using OpenAI’s ChatGPT to identify more than 50 bugs in the latest MacBook operating system within a three-week span. Among the reported issues was a privilege escalation exploit chain, a critical vulnerability that could enable an attacker to gain unrestricted system access and effectively take full control of an affected device. However, due to Apple’s submission restrictions, Bynario was initially unable to share the vulnerability with the company.

“It is a difficult time in the industry,” said Alfredo Pesoli, Bynario’s chief executive and co-founder, noting that software maintainers and technology vendors have been inundated by the sheer volume of security reports generated through AI assistance.

Apple confirmed it has since engaged with Bynario to review the firm’s submissions. The company emphasized that the adjustment in report limits aligns with a broader industry challenge posed by the rapid adoption of generative AI in cybersecurity. Apple also noted that researchers seeking to report additional bugs beyond the capped number can request approval for higher quotas.

In 2023, Apple expanded its bug bounty program, offering rewards of up to $5 million for detecting the most serious and complex security vulnerabilities in its software ecosystem. The new submission limits are part of the company’s efforts to maintain the integrity and effectiveness of this program amid the evolving landscape shaped by AI technologies.