2026-08-03

Apple Put a Quota on Bug Reports — and 11 Flaws in the Same Patch Batch Were Found by AI

On August 2 the Financial Times reported that Apple has imposed two limits on researchers who file security issues through Feedback Assistant: a cap on how many reports one person can keep open at a time, and a 30-day cool-off period once you hit it. Higher quotas require a separate request. Apple’s stated reason is that AI-assisted vulnerability reports are arriving faster than humans can verify them. Apple has not published the actual number.

One week earlier, on July 27, Apple shipped 8 security advisories and closed 210 vulnerabilities. Eleven of them were found by AI.

Those two things happened too close together to read separately.

Who got credited for those 11

Apple’s security advisories name the reporter. The July 27 batch credits:

The worst one in the batch is CVE-2026-64747 in AVEVideoEncoder — arbitrary code execution with kernel privileges, affecting everything from iPhone to Vision Pro. macOS Tahoe had seven more that reach root: two in CUPS, one each in Core Services, Accounts, SecurityAgent, Remote Management and MediaRemote.

The screen-sharing bug Atuin reported is CVE-2026-43760, and the firm behind it is the Italian company Bynario. Their Atlas platform runs on GPT-5.5 and turned up more than 50 candidate flaws in macOS in three weeks. The trigger conditions for this one are specific: the machine has Screen Sharing or Remote Management enabled along with legacy VNC password access, and an already-authenticated VNC client can then read protected data and create files as root — Bynario went on to demonstrate extending it to root command execution. Apple fixed it in macOS Tahoe 26.6 and credited three names: Alfredo Pesoli of Bynar.io, wdszzml, and Atuin, the machine.

The kind of submission Apple moved to limit yesterday and the batch of findings Apple thanked last week come from the same place.

Doubling the bounty and narrowing the door

In October 2025 Apple doubled its top bounty from $1 million to $2 million, for exploit chains that require no user interaction and approximate what mercenary spyware achieves. Bugs in beta software and Lockdown Mode bypasses carry bonuses that can push a single payout past $5 million. A one-click WebKit sandbox escape tops out at $300,000; a wireless proximity exploit at $1 million. The new schedule took effect in November 2025. Apple’s own cumulative figure: $35 million paid since 2020, to 800 researchers.

Less than a year later, Apple put a quota on the door.

One foot on the accelerator, one on the brake. Doubling the bounty tells the outside world to find more. The quota tells it to send less. Both signals go out at once, and whoever receives them has to guess which one is real.

Apple is not blind to where the bottleneck is. It now uses AI to triage and prioritise incoming reports, but confirmation is still human work — reproduce it, check the preconditions, judge the urgency. Finding bugs now runs in parallel on machines. Confirming them still runs serially through people. Until that middle step widens, more throttle upstream just piles up at the same place.

curl ran the opposite experiment

curl has run a bounty on HackerOne since 2019. For years, the share of submitted reports that turned out to be real vulnerabilities held above 15%. In 2025 it fell below 5% — more than nineteen out of every twenty reports were worthless. In July 2025 Daniel Stenberg estimated roughly 20% of submissions were pure AI slop.

He published a representative sample: a claimed vulnerability in HTTP/3, written up convincingly, complete with GDB sessions and register dumps. The only problem was that the function it referenced does not exist in curl.

We are effectively being DDoSed.

That is Stenberg. He also said something about why this cannot be solved by talking to people: we have no way to change how all these people and their slop machines work.

On January 26, 2026 he announced the end of the curl bounty. It stopped on January 31, and from February 1 security reports moved to GitHub. He was blunt about the motive:

The main goal with shutting down the bounty is to remove the incentive for people to submit crap and non-well researched reports to us.

Note which end he touched: the door stayed open, the money went away. Anyone can still report. Reporting just no longer pays.

Moving to GitHub he later judged a mistake. He listed fifteen defects in GitHub’s security advisory system, including that the full report goes out over email and notifications with no way to disable it, that invalid reports cannot be publicly disclosed, and that the CVE fields cannot be edited. On March 1 curl moved back to HackerOne — but the bounty did not come back. His words: the reward money is still gone, there is no bug-bounty.

What happened after the money left, in his phrasing: the inflow tsunami has dried out substantially. He did not declare victory. His very next line was that perhaps it just takes a while for all the sloptimists to figure out where to send the reports now.

Then curl simply shut the door for five weeks: July 1 at 00:00 CEST through August 3 at 09:00 CEST, no vulnerability reports accepted at all. Stenberg’s framing was that whatever you find this month, you will have to wait. That end time is this morning. curl just reopened.

GitHub took a third road

On July 27 — the same day Apple shipped those 210 fixes — GitHub’s new bounty schedule took effect. Public-track payouts were cut by at least half at every severity level; critical findings went from $20,000–$30,000-plus to a flat $10,000. Alongside it, GitHub opened a permanent invite-only tier paying $30,000 and up.

GitHub described the problem more precisely than Apple did. Alongside growth in legitimate reports, it said, came a sharp rise in submissions without a proof of concept, theoretical attack scenarios that do not hold up under scrutiny, and findings already covered by published ineligible lists.

It did not say those reports were written by AI. It said what those reports were missing. No PoC, no scrutiny, already-published non-issues.

There is a companion rule: newcomers are capped on how many reports they may submit until they have demonstrated quality. Build a record and the channel widens, ending at that invite-only tier. Per The Register, Google, Bugcrowd and HackerOne are restructuring along similar lines.

A quota acts on the person, not on the content

All three face the same change: writing a report that looks professional now costs close to nothing. They differ in which part of the machine they reached for.

curlGitHubApple
What movedBounty removed, channel left openPublic tier halved, high value moved to invite-onlyBounty raised to $2M+, quota on the submission door
What it acts onThe incentive to submitThe submitter’s track recordThe submitter
The costReal researchers no longer get paid eitherNewcomers must serve time to reach the high tierHigh-output teams and careless posters hit the same ruler

A quota is a blunt instrument because it counts how many reports you have open, not whether any of them holds. Bynario, which can produce 50 leads in three weeks, and a person pasting raw model output are the same class of account under a quota. For the first it blocks real throughput; for the second it blocks garbage. One rule, two opposite effects.

The bigger problem is that the category itself is wrong. The public framing has been “limiting AI-generated reports” — yet 11 of those 210 fixes on July 27 were found by AI, and one of them was reported by the very company that the coverage of this policy keeps naming. Who wrote a report and whether that report holds are two unrelated properties. Filter on the first and you will misfire in both directions at once.

Target Flags is the half Apple got right

There is another piece in Apple’s changes called Target Flags: researchers are asked to demonstrate that a flaw actually reached a specific target state, rather than describing a problem that ought to exist in theory.

A quota asks who you are and how many you have filed. Target Flags asks whether your thing runs. The first adds cost to the person; the second adds cost to the content. And AI happens to be extremely cheap at producing text that looks correct, and not much cheaper at getting a real exploit chain to work — a proof requirement lands exactly on that gap.

Stenberg’s removal of the bounty also moves proof cost, just denominated in opportunity: report it and you get nothing, so only people who actually want curl to be better will spend the time.

A quota does not sit on any cost gap at all. It sits on volume.

Who else is on this curve

Any place where open input meets human triage is sliding the same way:

These systems were all designed on one assumption: submissions are scarce, so humans can keep up. That stopped being true in 2026, and most products have not redesigned their intake since.

There are roughly three mechanisms available, and all three are running somewhere:

  1. A proof requirement — make the submitter produce evidence that generation cannot fake. Apple’s Target Flags and GitHub’s PoC demand are this.
  2. Reputation tiering — let historical accuracy set the width of your channel. GitHub’s invite-only tier plus the newcomer cap is the complete version: accurate people get $30,000, unproven people queue.
  3. A deposit or penalty — an invalid submission costs you something, pushing cost back to the sending end. Fraud-refund screening in e-commerce runs on this logic.

The quota ranks behind all three. It is the easiest to implement and the least sensitive to content.

There is a side effect on curl’s road worth naming: once the money is gone, the people who stay are more accurate, but there are fewer of them. For an open source project that is an acceptable trade. For a company relying on outside researchers to keep the iPhone standing, maybe not. Apple cannot remove the money, so it had to find another lever, and the first one it reached for was a quota.

Same people, same machines

The screen-sharing privilege escalation Apple closed on July 27, CVE-2026-43760, was reported by Bynario and a machine named Atuin. What Apple announced on August 2 is a limit on how fast those same people and that same class of machine can hand things in.

curl reopened at 09:00 this morning, still with no bounty. The last time Stenberg spoke publicly he did not say the problem was solved. He said maybe those people just have not figured out where to send it now.

One changed the incentive, one changed the gate. In three months it will be worth coming back to see which end of the numbers actually moved.

Discussion

No login needed. Be kind.
Loading…