Apple adds a 30-day cooldown to bug bounty submissions after AI floods the system with noise
量子位 · wechat · 2026-08-04
Apple has quietly added a cooling-off period to its bug bounty program after AI tools flooded it with low-quality vulnerability reports.
- Since the program’s 2016 launch, Apple has steadily raised rewards, including a 2025 top prize of $5 million for the most severe issues.
- But now many hobbyists use ChatGPT-style tools to mass-scan code and submit speculative reports, creating a huge review burden and lots of hallucinated bugs.
- Apple responded on Aug. 2 by capping submissions and imposing a 30-day cooldown in its internal security portal.
- The article ties this to a broader shift: AI is speeding up both offense and defense, but also clogging disclosure pipelines across the industry.
- Other vendors have reacted too: Google stopped accepting AI-generated reports, Nextcloud paused its bounty program, and GitHub cut public bounty payouts while creating a VIP path for invited researchers.
- Apple’s own security updates now credit AI tools, including Claude, OpenAI’s Codex Security, NVIDIA’s AI Red Team, and Z.ai’s GLM, for finding bugs faster.
More from Companies & People
- Cortex AI expands across three regions and hires for robot ops and engineering — DJiafei · 2026-08-04
- OpenAI's $51M Chip Deal with Altman-Backed Rain AI Faces Uncertainty — suchenzang · 2026-08-04
- Jensen Huang Says AI Could Lift Global GDP to $500 Trillion — rohanpaul_ai · 2026-08-04
- Mixedbread AI is building a smart database for AI agents — Scobleizer · 2026-08-04
- XYAI Labs says operational friction, not company size, is the real sign AI is ready — sam_debrouwer · 2026-08-04
- Editors need enough AI literacy to catch outdated research claims — eldonredwards · 2026-08-04