Apple's Cap on Vulnerability Submissions Criticized as AI Bug Reports Pile Up
Apple has introduced a cap and 30-day cooldown on vulnerability submissions, citing AI-generated bug reports. Security researchers say the limit helps no one because attackers face no such throttle.
Under the change, researchers who reach the cap must request an increased quota before submitting more reports. Apple said the problem was not limited to its own program and described AI-generated submissions as an industry-wide issue.
The policy drew criticism from Bradley Chambers, an Apple IT administrator and columnist for 9to5Mac. He said he understood the instinct to slow the flow but called the cap "the wrong response at exactly the wrong moment."
Chambers cited a Financial Times report about Bynario, a seven-person startup whose submissions were blocked after it had reported five bugs to Apple this year and eight in 2025. One of the 2025 reports was patched in November. Apple was reviewing Bynario's findings, including a privilege-escalation exploit chain that could let an attacker gain full control of a Mac. Chambers said the case showed why Apple should not cap submissions.
He also pointed to the Coldcard hack as a real-world example. Beginning in late July, attackers stole more than $116 million in Bitcoin from thousands of hardware wallet addresses. The root cause was a firmware bug introduced in March 2021 that silently caused the device to skip its hardware random number generator and fall back to a weaker software substitute when creating private keys. The bug went undiscovered for years. Chambers wrote that he believes AI tools were likely a factor in how the flaw was finally found and exploited, and that AI can surface years-old logic flaws that manual review might miss.
Chambers argued that attackers have no submission cap or cooldown period, so researchers should not have one either. If defenders are throttling the volume of AI-assisted research reaching their security teams while attackers do not have a throttle on AI-assisted attacks, he wrote, that creates a mismatch. He acknowledged that so-called AI slop bug reports are a real operational problem, but said the fix for a triage problem is better triage, not a slowdown that catches legitimate submissions.