HomeArticle

AI has carried out mass attacks on Apple's Bug Bounty Program, and the corresponding review team has been taken offline.

量子位2026-08-04 09:24
Apple has been forced to set up a "cooling-off period for bug submissions."

Apple has finally had enough and set a cooling-off period for its bug bounty program.

Urgent, there are too many bugs to review, what to do.... Haha, forget it! No more checking 😈.

The bug bounty program, launched in 2016, was originally designed to invite security researchers to submit security vulnerabilities in Apple's software, hardware and services, and they could get cash rewards after manual review and confirmation of validity.

Subsequently, the prize pool kept increasing. In October 2025, Apple announced a major upgrade to its bounty program: researchers who discover the most serious and complex threats can get 5 million US dollars (about 33.75 million RMB).

However, at present, AI has greatly lowered the threshold for finding vulnerabilities, and a large number of amateur players use ChatGPT to scan codes in batches and submit reports in batches, which are mixed with a large number of false vulnerabilities generated by AI hallucinations.

This has left Apple's entire security team completely overstretched.

On August 2, Apple has set a submission cap and a 30-day cooling-off period for vulnerability submissions on its internal security portal.

Apple's strongest defense system was easily breached by AI

In September 2025, Apple simultaneously announced a security feature called Memory Integrity Enforcement (MIE) at the iPhone 17 launch event.

This technology took five years to develop, is deeply integrated with the operating system based on the hardware capabilities of Apple's self-developed chips, and provides extreme memory security protection for devices.

Apple calls this feature:

the most significant upgrade in the history of memory security for consumer-grade operating systems.

Schematic diagram of MIE technical principle: How MIE blocks memory attacks

However, 8 months later, the cybersecurity industry experienced a collective cognitive shock.

In May 2026, security research firm Calif disclosed the first public vulnerability exploit for Apple M5 chip-based macOS. Its employees used Claude's Mythos Preview model to chain two macOS vulnerabilities into a complete local privilege escalation chain that bypasses MIE protection.

Moreover, the team (only 3 people) took only 5 days to go from "we found something interesting" to "we got a working root shell on Apple's most secure consumer-grade hardware".

The severity of this vulnerability eventually led two Calif researchers to drive to Apple's headquarters in person to submit a 55-page report, so as not to be drowned out by numerous submissions.

Mythos Preview, launched by Claude in April this year, is officially claimed to have achieved qualitative breakthroughs in security and programming fields, and has independently discovered thousands of high-risk vulnerabilities in "every" mainstream operating system and mainstream web browser. However, due to the model's "excessive offensive capabilities that will cause a major disaster if made public", its API is only open to 40 key partners.

Such rapidly developing AI technology is impacting the entire vulnerability disclosure ecosystem.

According to forecasts, the number of CVE (publicly disclosed cybersecurity vulnerability list) registrations in 2026 will reach 66,000, 46% higher than the original estimate.

However, just as Apple found out, these AI-generated vulnerability reports contain a lot of noise and AI hallucinations, and reviewing these reports has become a more energy-consuming task.

This is also a pain point for the entire security industry.

This is a rather difficult time for the industry, as maintainers and vendors are already overwhelmed by a flood of bugs.

The founder of Curl said he received 20 vulnerability reports in the first three weeks of 2026, of which "0 are real security vulnerabilities". Google announced in March that it would no longer accept AI-generated vulnerability reports; open source cloud platform Nextcloud suspended its bug bounty program in April; GitHub drastically cut the bounty amount for public bug bounties in July, and set up a VIP channel only for invited researchers.

This congestion in submission channels has already caused real security consequences, and may turn the security process itself into a security issue.

For example, Italian security startup Bynario used ChatGPT to discover more than 50 vulnerabilities in macOS within three weeks, including one that can fully take control of macOS.

However, when the team submitted this vulnerability that "can be sold for 100,000 to 200,000 US dollars on the black market", they found that Apple had blocked the submission entry.

Apple's security update acknowledges AI for the first time

The good news is: Defenders also have access to the same AI tools.

The bad news is: Defenders must maintain the normal operation of the entire IT environment, test compatibility, coordinate release windows, and ensure that updates do not crash production systems. What about attackers? They only need to find one entry point.

On July 27, 2026, Apple released the macOS Tahoe 26.6 security update. In this update, Apple fixed 194 independent security vulnerabilities.

This release also marks Apple's first official acknowledgment of AI in security fixes.

Discovered in collaboration with Claude

Among them, Anthropic's Claude and OpenAI's Codex Security were each credited for three vulnerabilities, NVIDIA's AI Red Team was credited for two, and Z.ai's GLM model was credited for one.

(Although three weeks ago, Apple was suing OpenAI in court for stealing trade secrets.)

Apple publicly stated that AI tools have accelerated the speed of our security update release. From the security update data since the release of macOS Tahoe, we can see the outline of this acceleration trend:

The 26.5 version already featured credits for AI tools; 26.5.2, as an unconventional minor update, added fixes for 38 more CVEs; 26.6 was released a month later, once again setting a new record with 155 fixes.

However, it is uncertain whether this high-frequency release rhythm itself will become a new security variable?

After all, Apple is known for its strict control over the release rhythm. Every system update must go through internal testing, compatibility verification, and phased gray release before being pushed to billions of devices.

In this light, accelerating the release pace is not a reckless decision, it means Apple's security team has judged that the risk of waiting until the next regular update window to fix these vulnerabilities is no longer acceptable.

The vulnerability disclosure cycle is already transforming. When AI compresses the vulnerability discovery cycle to several days, the monthly security update release rhythm may become a lengthy "exposure period".

References:

[1]https://security.apple.com/blog/apple-security-bounty-evolved/

[2]https://security.apple.com/blog/memory-integrity-enforcement/

[3]https://support.apple.com/en-us/128067

[4]https://www.ft.com/content/4532122d-90f2-4433-9df6-ca99d8a141d2

This article is from the WeChat Official Account "QbitAI" (ID: QbitAI), written by Cheng Qian, authorized for release by 36Kr.