リーディングビュー

Apple Limits Bug Bounty Submissions After Flood of AI Slop

✇Slashdot
著者: BeauHD

🤖 AI Summary

APPLEは、AIによって生成された低品質なバグ報告が大量に寄せられることで対応を難しくしている。セキュリティ企業のBynarioは、ChatGPTを使用して3週間で50以上のmacOS脆弱性を見つけたが、Appleが提出できるバグ報告数を制限したことから、重要な脆弱性(権限上昇型)を報告できなかった。

AppleはBynarioに対して連絡を取り、その報告書の審査を行っている。現在、研究者が開いた未解決のバグ報告の数に上限が設けられたが、重大な脆弱性を見逃さないよう必要に応じて上限を上げることができるという。

業界では「非常に難しい時期」にあるとし、大量の脆弱性により企業が脅威にさらされていると述べている。
Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction. Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.

Read more of this story at Slashdot.

  •  
❌