Skip to main content
  1. Home
  2. Computing
  3. News

AI is finding Apple security flaws faster than Apple can sort through them

Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions

Add as a preferred source on Google
Lighting, Architecture, Building
Bangyu Wang / Unsplash

Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under pressure, according to the Financial Times.

Some submissions describe hallucinated or purely theoretical risks. Others uncover vulnerabilities serious enough to require patches. Bynario told the FT that it found more than 50 possible macOS flaws in three weeks, including a privilege-escalation chain that could give an attacker full control of a Mac.

Recommended Videos

Every report still needs human verification, although Apple is now using AI to help triage the backlog. Finding possible weaknesses is getting easier. Working out which ones pose an immediate threat has become the harder job.

How real are the AI-found flaws

Bynario has already shown that its system can produce more than automated guesswork. Its Atlas platform used GPT-5.5 to uncover a macOS Screen Sharing flaw that let an authenticated VNC viewer access protected data and create files with root privileges.

The attack required Screen Sharing or Remote Management to be enabled, along with legacy VNC password access. Apple assigned it CVE-2026-43760 and patched it in macOS Tahoe 26.6.

Bynario also demonstrated how the flaw could be extended to run commands as root. That gave Apple a working exploit to investigate rather than another vague warning generated from a code scan.

Why Apple needs the same AI

Apple’s recent security advisories credit researchers working with Claude for a kernel vulnerability. OpenAI Codex Security has also helped identify several WebKit issues.

AI-assisted research is already contributing to fixes shipped for macOS and Safari. Restricting submissions too aggressively could delay useful discoveries, while leaving the gates open risks burying Apple’s team under convincing-looking nonsense.

The bottleneck is verification. Models can generate possible attack paths quickly, but Apple still has to reproduce the behavior, confirm the required conditions and decide how urgently it needs a fix.

Can Apple keep the signal

Apple has redesigned its bug bounty program around stronger evidence. Its maximum payout now exceeds $5 million for the most serious exploit chains, while Target Flags help researchers prove that a flaw reaches protected parts of the system.

That gives Apple a better way to separate demonstrated exploits from automated speculation. Mac users can’t solve the reporting backlog, but they can limit their exposure by installing security updates promptly. AI bug hunting is already finding flaws that reach Apple’s patch queue.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Windows 11 is about to turn on a setting that could hurt gaming performance
Microsoft will start enabling Memory Integrity on more Windows 11 PCs in October
A gaming PC with RGB synced lights running Apex Legends.

Microsoft is preparing to enable Memory Integrity on more Windows 11 PCs starting in October. The security feature is meant to protect systems from malicious code, but there is one reason gamers may want to keep an eye on it.

Microsoft has previously acknowledged that Memory Integrity can affect gaming performance on some Windows 11 systems. Back in 2022, the company even published instructions explaining how gamers could temporarily disable Memory Integrity and Virtual Machine Platform if they were causing problems.

Read more
AI chatbots will agree and misinform if you just put a little pressure, warns research
ChatGPT 3.5 proved the most vulnerable when false claims were repeated over and over
Claude AI on an iPhone.

AI chatbots have a well-documented habit of hallucinating information and sometimes agreeing with users even when they are wrong. A new study suggests that simply refusing to take no for an answer can make the problem worse.

Researchers from the University of Arizona tested seven AI models, including GPT-3.5, GPT-4o, GPT-4o-mini, Claude 3.5 Sonnet, Gemini 1.5 Pro, Llama 3 70B, and DeepSeek-R1. Instead of judging them from a single response, researchers kept conversations going while repeatedly feeding the models information they knew was false.

Read more
Google brings its best AI music model Lyria 3.5 to the Gemini app
Developers get full API access through Google AI Studio.
Google-gemini-lyria-3.5

Google has added Lyria 3.5, its most advanced music generation model yet, to the Gemini app. Previously available through Google's AI filmmaking tool Flow, the model is now rolling out to all Gemini users, making it easier to generate polished songs, instrumentals, and soundtracks from simple text prompts or even photos.

Lyria 3.5 makes AI-generated music sound more natural

Read more