Apple has implemented new limitations on its bug bounty program due to an influx of submissions generated by artificial intelligence. The company is now capping the number of reports a single party can submit and imposing a 30-day cool-off period, requiring special requests for further submissions beyond the cap. This move follows similar adjustments by Google, which also revised its program to prioritize complex, human-discovered vulnerabilities over easily identifiable AI-generated ones. The surge in AI-generated reports has reportedly overwhelmed review teams and risked obscuring genuine security flaws. AI
IMPACT AI-generated content is overwhelming security review processes, forcing companies to adapt their bug bounty programs.
RANK_REASON Company policy change in response to AI tool usage.
Read on Mastodon — fosstodon.org →
AI-generated summary · Google Gemini · from 10 sources. How we write summaries →