Bottom line: Apple's bug bounty program is at risk of missing serious security vulnerabilities due to the high volume of low-quality submissions.
What's happening: In 2022, researchers at Google discovered that AI-powered tools could generate reports of non-existent security flaws, with 42% of such reports coming from a single tool, known as DeepCode. Apple's portal has seen a significant increase in such submissions, prompting the company to impose new limits.
What to do: Security leaders should review their own bug bounty programs to ensure they are not vulnerable to AI-generated reports and implement measures to detect and prevent such submissions.