
Apple Caps Bug Bounty Submissions as AI-Generated Reports Flood the Queue
Apple has imposed a submission cap and 30-day cool-off period on its bug bounty program after AI-generated security reports overwhelmed review teams, risking genuine vulnerabilities found by human researchers being buried. Researchers exceeding the cap must file a special request. Rewards reach $200,000 for critical bugs. Google, facing the same pressure, restructured its payout tiers to reward harder-to-find bugs AI tools struggle to surface.
Published