As it grapples with a surge in “AI slop” security reports, Apple has recently made changes to its bug bounty program. Here are the details.

Apple limits number of open vulnerability reports

Apple has confirmed to The Financial Times that it has “introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota.”

Implemented in June, the changes are intended to address an industry-wide surge in bug reports, driven by increasingly powerful LLMs that can find, chain, and exploit vulnerabilities, leaving review teams struggling to keep pace with the volume of submissions.

Just a few weeks ago, Apple confirmed that it was accelerating security updates in response to these AI tools, releasing fixes in iOS 26.5.2 and its counterparts that had originally been planned for last week’s version 26.6 updates.