Apple's Security Bounty pays up to $5M per serious flaw. In June 2026 it imposed a cap on concurrent open reports after AI assisted submissions surged, and a critical Mac vulnerability almost got buried.
An Italian research group called Bynario used ChatGPT to surface roughly 50 bugs in macOS 26, including one that would have given an attacker full control of a Mac. After the group filed eight reports in 2025 and five more in 2026, Apple stopped accepting their submissions. Apple later confirmed to the Financial Times that it is now reviewing the latest batch.
The Bynario case sits inside a broader policy shift. In June 2026, Apple imposed a cap on the number of open reports a researcher can have at once in its Security Bounty program, with a 30-day cool-off after a report closes. Researchers can request additional quota for critical issues, but Apple has not published the cap number, the criteria, or whether high-severity reports jump the queue (9to5Mac, MacRumors).
Apple's stated rationale: "With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once." The cap applies to a program that pays up to $5 million per serious vulnerability across iOS, macOS, and other Apple services (The Verge).
The open question is what good policy looks like when AI-assisted research is the norm. Apple has chosen triage rationing; the cap number, the escalation path, and the audit trail remain undisclosed.