Apple’s bug bounty program has introduced a cap on the number of open vulnerability reports researchers can file, a change that has drawn scrutiny as artificial intelligence reshapes how software flaws are discovered. Apple confirmed the limit, which pairs a submission ceiling with a 30-day cool-down period once a researcher reaches it.
The company put the cap in place in June through its internal security portal. Once researchers hit the ceiling, they must request an increased quota to continue submitting reports. Apple attributes the move to a flood of AI-generated bug reports overwhelming its review pipeline, and describes the challenge as an industry-wide issue.
How the Cap Works
Large language models can now identify vulnerabilities quickly and with a level of thoroughness that manual human review often cannot match. That capability has produced a sharp rise in submission volume, and security review teams across the industry are struggling to keep pace.
The tradeoff, however, is that legitimate researchers can find themselves shut out. A seven-person startup called Bynario had its submissions blocked after reporting five bugs to Apple this year and eight in 2025, one of which was patched in November. Apple is now reviewing Bynario’s findings, which include a privilege-escalation exploit chain capable of giving an attacker full control of a Mac.
The Coldcard Hack Raises the Stakes
The timing of the cap coincides with mounting evidence that AI tools are accelerating the discovery of long-dormant software flaws. A prominent example is the Coldcard hack. Beginning in late July, attackers drained more than EUR 100 million in Bitcoin from thousands of hardware wallet addresses.
The root cause traced back to a firmware bug introduced in March 2021, five years earlier. The flaw silently caused affected devices to skip their true hardware random number generator, falling back to a much weaker software substitute when generating private keys. The vulnerability remained undiscovered and unexploited for years before it was found and abused at scale.
The Coldcard case illustrates a broader shift in security research. AI-assisted analysis can surface years-old logic flaws buried in code that human researchers might never uncover through manual inspection alone. That same power fuels both defenders and attackers, raising questions about whether restricting the flow of vulnerability reports serves security in the long run.
Apple’s cap took effect in June and remains in place, with researchers required to request quota increases once they reach the submission limit.
Source
Image: 9to5mac.com