AI批量轰炸苹果bug赏金计划,审核团队已下线
Ranking
Overall
40
Content
35
Popularity
N/A
No observed public metrics; popularity remains neutral/archived.
Merged summary
TL;DR - Apple has throttled its bug bounty program with submission caps and a 30-day cooling-off period after AI-assisted researchers flooded it with reports, many of them hallucinated — a signal that AI-driven vulnerability discovery is outpacing human triage capacity across the industry.
- On Aug 2, Apple imposed submission quotas and a 30-day cooling period on its internal security portal; its bounty had been raised to a $5M top payout in Oct 2025.
- Apple's Memory Integrity Enforcement (MIE), a five-year hardware/OS memory-safety effort shipped with iPhone 17, was reportedly bypassed on M5 macOS by a 3-person team at Calif in ~5 days using Claude's restricted "Mythos Preview" model, chaining two bugs into a local privilege-escalation root shell.
- The triage bottleneck is industry-wide: curl's founder reported 20 submissions and 0 real bugs in early 2026; Google stopped accepting AI-generated reports (March), Nextcloud paused its bounty (April), GitHub cut payouts and moved to an invite-only VIP channel (July); 2026 CVE volume is projected at ~66,000 (+46% over prior estimates).
- Defensively, macOS Tahoe 26.6 (July 27, 2026) fixed 194 issues and marked Apple's first formal AI credits — Anthropic's Claude and OpenAI Codex Security (3 each), NVIDIA AI Red Team (2), Z.ai GLM (1) — with Apple saying AI tools accelerated its release cadence, raising open questions about the risk of faster shipping.
Sources (1)
AI批量轰炸苹果bug赏金计划,审核团队已下线
Public signals
N/A
TL;DR - Apple has throttled its bug bounty program with submission caps and a 30-day cooling-off period after AI-assisted researchers flooded it with reports, many of them hallucinated — a signal that AI-driven vulnerability discovery is outpacing human triage capacity across the industry.
- On Aug 2, Apple imposed submission quotas and a 30-day cooling period on its internal security portal; its bounty had been raised to a $5M top payout in Oct 2025.
- Apple's Memory Integrity Enforcement (MIE), a five-year hardware/OS memory-safety effort shipped with iPhone 17, was reportedly bypassed on M5 macOS by a 3-person team at Calif in ~5 days using Claude's restricted "Mythos Preview" model, chaining two bugs into a local privilege-escalation root shell.
- The triage bottleneck is industry-wide: curl's founder reported 20 submissions and 0 real bugs in early 2026; Google stopped accepting AI-generated reports (March), Nextcloud paused its bounty (April), GitHub cut payouts and moved to an invite-only VIP channel (July); 2026 CVE volume is projected at ~66,000 (+46% over prior estimates).
- Defensively, macOS Tahoe 26.6 (July 27, 2026) fixed 194 issues and marked Apple's first formal AI credits — Anthropic's Claude and OpenAI Codex Security (3 each), NVIDIA AI Red Team (2), Z.ai GLM (1) — with Apple saying AI tools accelerated its release cadence, raising open questions about the risk of faster shipping.