Apple Limits Bug Bounty Submissions

l-intro-1785868965

Apple has implemented new restrictions on its security bug bounty program to manage a high volume of AI-generated vulnerability reports.

  • New Policy: Apple introduced a cap on concurrent open vulnerability reports and a 30-day cooldown period for researchers.
  • Implementation: The changes were enacted in June to address a surge in low-quality or hallucinated findings from LLMs.
  • Exemptions: Researchers can request increased submission quotas for critical security findings.