The cap has already cost it a real one. Milan-based cybersecurity startup Bynario told the paper it used OpenAI's ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine.
Bynario could not report it, because Apple had already refused further submissions. Chief executive Alfredo Pesoli put the exploit's value on the criminal market at between $100,000 and $200,000, and said "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple told the FT
Apple moved in June, adding a cap and a 30-day cool-off period on its security portal, with researchers required to apply for a bigger quota. Every alleged flaw still needs a human to confirm it, though Apple is using AI internally to triage the pile. Apple said it had "recently adjusted the number of new reports a researcher can have open at once," and that researchers can ask for a higher limit at any time.
A “submission flood”The volume is driven by the rewards on offer, with Meta, Microsoft, Apple and Crypto.com paying out at least $58 million between them in 2025, while Apple's own top tier reaches $5 million for a single finding.
Instead of filing a report, Calif carried the exploit to Apple's California headquarters in person, saying it wanted to avoid "getting buried in the submission flood" that entrants in hacking contest Pwn2Own had been caught in. Bynario tried the portal three months later and could not get in.
AI crypto threats

















