Apple's bug report cap blocked a real macOS flaw
Apple capped researcher submissions after a flood of AI-generated security reports — and a genuine macOS privilege escalation couldn't get through. Rate limits cut both ways.
Apple capped how many open bug reports a security researcher can have at once and added a 30-day cooling-off period once you hit it. The reason is AI-generated submission volume. The result, reported alongside the policy, is the part worth studying: a researcher sitting on a real macOS privilege escalation chain couldn't file it, because the quota was already spent.
What actually happened
The Financial Times first reported the change, which Apple made quietly in June. Apple's statement, as covered by Neowin and others, points at the industry rather than any one researcher: with the growing volume of AI-generated security submissions, it adjusted how many new reports a researcher can have open at once. Researchers can request a higher quota at any time.
The case that makes it concrete: Italian security startup Bynario used ChatGPT to find a macOS privilege escalation chain that would give an attacker full control of a machine. It couldn't submit — quota exhausted. CEO Alfredo Pesoli put the flaw's black-market value at $100,000 to $200,000, per The Decoder. Apple has since contacted Bynario directly.
Apple is also running AI on its own side of the queue, using models from Anthropic and OpenAI to hunt vulnerabilities and triage what comes in.
Why AI-generated submission volume matters for your business
The lesson isn't "AI reports are noise." Bynario's find was real, and it came out of ChatGPT. Both things are true at once, and that's exactly what makes this hard: the same tool that generates the slop generates the good stuff, and they arrive in the same envelope.
A rate limit is an honest admission that you can't tell them apart yet. It buys time and it costs you your best sources, because volume correlates with effort, and the people doing the most work hit the ceiling first. Apple could afford that trade because it can pick up the phone afterward. You probably find out you throttled a good lead when the lead goes somewhere else.
If you run any intake — support, leads, applications, warranty claims, vendor pitches — the durable fix is to spend your scarce human attention on verification, not on reading. Three moves that work at small scale: build a fast lane for known-good senders so a proven customer or repeat referrer never queues behind a cold submission. Score by cost-to-verify rather than claimed urgency, so the thing you can confirm in two minutes clears ahead of the thing that takes an hour. And when you do cap something, make the cap appealable in-band — a "request more" link in the rejection is what saved Apple here, and it costs one form.
The volume isn't going back down. Design the queue for that.
Key takeaways
- Apple capped open bug reports per researcher with a 30-day cool-off, made in June, first reported by the Financial Times
- The driver is AI-generated security submissions; Apple now uses Anthropic and OpenAI models to triage incoming reports
- Bynario found a genuine macOS privilege escalation chain with ChatGPT and couldn't file it — CEO estimates $100K–$200K black-market value
- Rate limits throttle your best sources first, because effort correlates with volume
- For your own intake: fast-lane known-good senders, prioritize by cost-to-verify, and always make a cap appealable in-band
A queue that treats every submission the same is a queue that loses the good ones. We build intake routing that scores on reputation and verification cost, so your team spends its hours confirming, not reading. See what we build, or show us the queue that's drowning.
Sources: Neowin, The Decoder.
- #security
- #ai-agents
- #operations
- #vulnerability-management
- #apple
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TLS 1.2 is frozen: post-quantum ships only in TLS 1.3
The IETF published RFC 9851 putting TLS 1.2 in feature freeze. Post-quantum crypto will never be specified for it. Here's how to find what in your stack is stuck.
Read itN-able N-central exploited — patch the console that runs your IT
CVE-2026-18577 is an actively exploited auth bypass in N-able N-central RMM. The first fix didn't hold. Upgrade to 2026.3.1.7 and check your MSP's version.
Read it