BlockBeats News, August 2nd, according to the Financial Times, Apple has restricted the number of vulnerability reports submitted by researchers after receiving a surge in reports from researchers using AI models to find software bugs. Since June, researchers are limited in the number of vulnerabilities they can submit simultaneously and are subject to a 30-day cool-off period. Apple stated that some AI-generated reports fabricate security risks, putting a strain on the review system.
Italian cybersecurity startup Bynario stated that using OpenAI's ChatGPT, they discovered over 50 vulnerabilities in the latest version of the MacBook operating system in just 3 weeks. This included a privilege escalation attack chain that could allow an attacker to gain full control of an Apple computer system. However, due to Apple's limit on the number of reports, the company was initially unable to submit the relevant vulnerabilities. Apple has mentioned that they are now in contact with Bynario and have started the review process.
Apple mentioned that each security report still requires human confirmation, and the company is also using AI internally to classify the influx of reports. Researchers can apply to increase their submission quota to ensure that critical vulnerabilities reach the security team. Bynario estimates that the privilege escalation vulnerability they discovered could be worth between $100,000 and $200,000 on the cybercrime black market.
Last year, Apple introduced a new bug bounty reward mechanism that can pay up to $5 million for discovering the most severe and complex threat categories in its software.
In the system security updates released by Apple this week, it was also revealed that Anthropic and OpenAI's tools helped discover multiple device vulnerabilities, with this round of fixes being about 5 times the usual update cycle. Security company Sophos stated that AI is both enhancing the efficiency of real vulnerability discovery and generating a large number of low-quality reports, shifting the challenge of bug bounty programs from "finding vulnerabilities" to rapid validation, prioritization, and response.
