Apple's Vulnerability Cap Blocks $200K macOS Exploit Report
In brief
- Bynario discovered 50+ macOS bugs using ChatGPT, including a $100K–$200K privilege escalation exploit.
- Apple capped vulnerability submissions in June to combat AI-generated false reports and implemented a 30-day cool-off period.
- Bugcrowd submissions quadrupled in March; HackerOne and Nextcloud suspended bounty programs as AI models surface real flaws.
The Submission Flood
Bynario used OpenAI's ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine. Bynario Chief Executive Alfredo Pesoli valued the exploit at between $100,000 and $200,000 on the criminal market.
The problem: Bynario could not report it, because Apple had already refused further submissions. Apple moved in June, adding a cap and a 30-day cool-off period on its security portal, with researchers required to apply for a bigger quota. The policy shift didn't come from nowhere.
"Maintainers and vendors have been flooded by the sheer amount of bugs," Pesoli said.
Earlier this year, the industry saw why. In May, security firm Bugcrowd reported that submissions through its platform more than quadrupled across three weeks in March, with most being fake. HackerOne and Nextcloud suspended their paid bug bounty programs in April due to AI-generated submissions. Vendors were drowning in noise.
The Paradox: Real Flaws, Real Fast
Yet AI is also finding genuine vulnerabilities—and fast. In security updates last week, Apple credited Anthropic and OpenAI software with surfacing flaws, and carried roughly five times the fixes of a normal cycle. Apple uses AI internally to triage vulnerability submissions, though every alleged flaw still needs human confirmation.
The stakes are enormous. Meta, Microsoft, Apple and Crypto.com paid out at least $58 million in bug bounties between them in 2025, while Apple's own top tier reaches $5 million for a single finding. This year, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing. Mozilla said it surfaced 271 vulnerabilities in Firefox during internal testing.
Other researchers have bypassed the bottleneck entirely. Vietnam-based security startup Calif said it had used a preview version to build the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement. Rather than risk getting buried in the submission flood, Calif carried the exploit to Apple's California headquarters in person.
The Crypto Angle
The AI-vulnerability boom has already reshaped the security landscape. Coldcard wallet manufacturer Coinkite has suggested that AI was likely used to uncover a bug in its open source firmware that sat unnoticed for five years, enabling attackers to steal more than $100 million. Researcher Taylor Hornby, working with Claude Opus 4.8, had found two lines of code in its Orchard shielded pool that allowed undetectable counterfeiting of ZEC for four years, prompting Zcash to roll out the Ironwood upgrade last month to address the vulnerability.
Apple's submission cap was meant to restore signal. Instead, it's blocking real researchers from reporting real flaws—and forcing some to walk them in person.


