Apple limits bug bounty submissions, raising concerns among security researchers
Apple has capped vulnerability report submissions from security researchers to manage the influx of AI-generated reports, imposing a 30-day cooldown after reaching the limit. Critics argue this approโฆ
Apple has introduced a cap on the number of vulnerability reports that security researchers can submit through its platform. This new policy, which includes a 30-day cooldown period after reaching the cap, comes in response to a significant increase in AI-generated bug reports that have overwhelmed the company's review process.
The decision to limit submissions is seen as an attempt to manage the influx of reports, which Apple claims has been exacerbated by the rise of artificial intelligence. As AI tools become more sophisticated, they can generate numerous bug reports quickly, flooding the system and making it challenging for Apple to prioritize and address legitimate security issues. However, critics argue that capping submissions is a misguided response, particularly at a time when cybersecurity threats are on the rise.
Apple's move raises concerns within the security community. Researchers worry that limiting submissions could prevent the discovery of critical vulnerabilities. With cybersecurity threats evolving rapidly, especially with the integration of AI across various platforms, having an open channel for reporting issues is vital for maintaining security integrity. The cap may discourage researchers from reporting vulnerabilities, fearing their efforts could be wasted or ignored due to the limit.
This policy shift could have long-term implications for Apple's security strategy. As the tech giant navigates an increasingly complex threat landscape, fostering collaboration with researchers is essential. A more open approach to vulnerability reporting may enhance security and build trust within the tech community. As AI continues to shape the future of technology, Apple must find a balance between managing submissions and encouraging cybersecurity research to stay ahead of potential threats.
Read Full Story at 9to5Mac โ


