Apple has finally had enough, setting a cooling-off period for its own bug bounty program.
Urgent, too many bugs to review, what to do.... Haha, forget it! I'm not looking anymore 😈.
The bug bounty program, introduced in 2016, originally aimed to invite security researchers to submit security vulnerabilities in Apple's software, hardware, and services, with cash rewards offered upon manual review and confirmation of validity.
Subsequently, the prize pool kept increasing. In October 2025, Apple announced a major upgrade to the bounty program: researchers discovering the most severe and complex threats could receive $5 million (approximately ¥33.75 million).
However, currently, AI has significantly lowered the barrier to finding vulnerabilities. Numerous amateurs are using ChatGPT to batch-scan code and batch-submit reports, which are riddled with a large number of AI-hallucination-style false positives.

This has left the entire Apple security team completely overwhelmed.
On August 2nd, Apple has already implemented submission caps and a 30-day cooling-off period for vulnerability submissions on its internal security portal.
Apple's Strongest Defense System Easily Overwhelmed by AI
In September 2025, Apple announced a security feature called "Memory Integrity Enforcement" (MIE) alongside the iPhone 17 launch event.
This technology, developed over five years, is based on the hardware capabilities of Apple's in-house chips and deep integration with the operating system, providing ultimate memory security protection for devices.
Apple described the feature as:
The most significant upgrade to memory security in the history of consumer-grade operating systems.

Diagram of MIE technical principle: How MIE prevents memory attacks
However, eight months later, the cybersecurity industry experienced a collective cognitive shock.
In May 2026, security research company Calif disclosed the first public exploit for Apple's M5 chip on macOS. Its employees, leveraging Claude's Mythos Preview model, chained two macOS vulnerabilities into a complete local privilege escalation chain, bypassing MIE's protection.
Moreover, the team (only 3 people) went from "we found something interesting" to "we had a working root shell on Apple's most secure consumer-grade hardware" in just 5 days.
The severity of this vulnerability ultimately led Calif's two researchers to personally drive to Apple's headquarters to hand-deliver a 55-page report, to avoid being buried in the flood of reports.
Mythos Preview, launched by Claude in April this year. The company claims it has achieved a qualitative breakthrough in security and programming fields, and has autonomously discovered thousands of high-risk vulnerabilities in "every" mainstream operating system and mainstream web browser. However, due to the model's "offensive capabilities being too strong, public release would cause a major disaster," the API is only available to 40 key partners.
Such rapidly advancing AI technology is impacting the entire vulnerability disclosure system.
It is predicted that CVE (Common Vulnerabilities and Exposures) registrations for 2026 will reach 66,000, 46% higher than original estimates.

However, as Apple discovered, these AI-generated vulnerability reports contain a lot of noise and AI hallucinations. And reviewing these reports has become an even more energy-draining task.
This is also a pain point for the entire security industry.
This is a rather difficult period for the industry, maintainers and vendors are already inundated with bugs.
The founder of Curl stated that in the first three weeks of 2026, he received 20 vulnerability reports, of which "0 were actual security vulnerabilities." Google announced in March that it would no longer accept AI-generated vulnerability reports; the open-source cloud platform Nextcloud paused its bug bounty program in April; GitHub significantly reduced the bounty amounts for public bug bounties in July and established an invite-only VIP channel for researchers.
This congestion in submission channels has already produced real security consequences, potentially turning the security process itself into a security problem.
For example, Italian security startup Bynario used ChatGPT to discover over 50 vulnerabilities in macOS within three weeks. Among them was a vulnerability that could completely control macOS.
However, when the team attempted to submit this "could sell for $100,000 to $200,000 on the black market" vulnerability, they found Apple had already blocked the submission entry.
Apple's First Time Acknowledging AI in Security Updates
The good news is: defenders also get the same AI tools.
The bad news is: defenders must maintain the normal operation of the entire IT environment, test compatibility, coordinate release windows, and ensure updates don't crash production systems. And the attackers? They just need to find one entry point.
On July 27, 2026, Apple released the macOS Tahoe 26.6 security update. This update fixed 194 individual security vulnerabilities.
This release also marks Apple's first formal acknowledgment of AI in security fixes.

Discovered in collaboration with Claude
Among them, Anthropic's Claude and OpenAI's Codex Security each received acknowledgments for three vulnerabilities, NVIDIA's AI Red Team received two, and Z.ai's GLM model received one acknowledgment.
(Even though three weeks prior, Apple was in court suing OpenAI for stealing trade secrets.)
Apple publicly stated that AI tools have accelerated the release speed of our security updates. We can see the outline of this acceleration trend from the security update data since the release of macOS Tahoe:
The 26.5 version already included attributions to AI tools; 26.5.2, as an irregular minor version update, added fixes for another 38 CVEs; 26.6 was released a month later, setting a new record again at 155 fixes.
However, what remains uncertain is whether this high-frequency release rhythm itself will become a new security variable?
After all, Apple has always been known for strictly controlling its release rhythm. Every system update undergoes internal testing, compatibility verification, and phased staged rollout before being pushed to billions of devices.
Viewed this way, accelerating releases is not a rash decision; it signifies that Apple's security team has judged that the risk of waiting until the next regular update window to fix these vulnerabilities is no longer acceptable.
The vulnerability disclosure cycle is already deforming. When AI compresses the vulnerability discovery cycle to a matter of days, the monthly security update rhythm may turn into a long "exposure window."
Reference Links:
[1]https://security.apple.com/blog/apple-security-bounty-evolved/
[2]https://security.apple.com/blog/memory-integrity-enforcement/
[3]https://support.apple.com/en-us/128067
[4]https://www.ft.com/content/4532122d-90f2-4433-9df6-ca99d8a141d2
This article is from the WeChat public account "QbitAI" (ID: QbitAI), author: Cheng Qian








