Apple's Bug Bounty Program Overwhelmed by AI-Generated Reports

Apple has tightened its bug bounty program's submission limits after discovering a significant influx of low-quality reports, including those generated by artificial intelligence.

Bottom line: Apple's bug bounty program is at risk of missing serious security vulnerabilities due to the high volume of low-quality submissions.

What's happening: In 2022, researchers at Google discovered that AI-powered tools could generate reports of non-existent security flaws, with 42% of such reports coming from a single tool, known as DeepCode. Apple's portal has seen a significant increase in such submissions, prompting the company to impose new limits.

What to do: Security leaders should review their own bug bounty programs to ensure they are not vulnerable to AI-generated reports and implement measures to detect and prevent such submissions.

Source: Graham Cluley