Product1 distinct publisher3 min readPublished
Apple says AI-generated submissions are flooding its review pipeline, so it capped open vulnerability reports and added a 30-day cool-down. The one blocked researcher named so far had filed 13 reports across two years.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Hit the ceiling and the next move is paperwork: ask Apple for a bigger quota, or wait out 30 days [2]. The number that ceiling sits at does not appear in the account published by 9to5Mac's Bradley Chambers, an Apple IT admin since 2009 [15][16]. That is the practical problem for a researcher holding something live. You cannot pace disclosures against a limit you can only find by tripping it.
In the one case with a name attached, the volume that tripped it was small. Bynario, a seven-person startup, filed five reports to Apple this year and eight in 2025 before its submissions were blocked, according to a Financial Times report cited by Chambers [5]. That is 13 reports in total [13], roughly 1.9 per employee across the whole period [14]. One of them was patched in November [6]. Apple is reviewing the firm's findings now, including a privilege-escalation exploit chain that could give an attacker full control of a Mac [7]. The column places the block first and the review after the FT wrote it up, and does not say the coverage caused the review [5][7].
Chambers' argument against the cap runs through Coldcard. From late July, attackers drained more than $116 million in bitcoin from thousands of hardware wallet addresses [8], and the root cause was a firmware bug shipped in March 2021 that quietly made the device skip its true hardware random number generator and fall back to a weaker software substitute when generating private keys [9]. He writes that he believes AI tools were likely a factor in the flaw finally being found and exploited at scale [10]. No evidence for that link appears in the piece, so read it as his inference rather than a finding. What holds up without it is the asymmetry he names: attackers get no 30-day cool-off between attempts [12].
For anyone running vulnerability intake, a count cap is the cheapest throttle to build, and the cheapest one is the one that treats every submitter as the same submitter. Two axes are worth drawing before copying it: cost to file, and cost to review. Machine-generated slop is cheap to file and expensive to review. A Bynario-style exploit chain is expensive in both directions. A per-account count cannot separate those, because it never looks at who is filing. A quota weighted by submitter history can, and Apple's quota-increase request is the manual version of that, with the researcher carrying the wait. Chambers' verdict is that the fix for a triage problem is better triage rather than slower submission [11].
Security leads cannot yet say that disclosure to Apple takes longer end to end; the column reports no measured change in fix times [17]. What it does document is one queue closing on one small firm sitting on a full-control Mac exploit chain [5][7]. The number worth knowing about your own intake is how many days your best-known outside reporter needs to get an urgent finding past your throttle, counted from the day they hit it. If the shortest path on record runs through a journalist, escalation has quietly been outsourced.
Ranked by verification strength, evidence, and original report placement.
Apple confirmed it has capped the number of open vulnerability reports researchers can submit through its portal, with a 30-day cool-down period once the cap is hit.
Apple introduced the cap and 30-day cooldown on submissions through its internal security portal in June, requiring security researchers to request an increased quota if they hit the cap.
Apple's stated reason for the cap is a surge in AI-generated bug reports flooding its review pipeline.
Apple says the flood of AI-generated vulnerability reports is an industry-wide problem, and Chambers agrees review teams everywhere are struggling to keep pace with the volume.
A Financial Times report, as cited by 9to5Mac, says Bynario, a seven-person startup, had its submissions blocked after reporting five bugs to Apple this year and eight in 2025.
One of the bugs Bynario reported to Apple was patched in November.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 5, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
IT's AI shopping list is inverted: 46.5% want automation, 71% of their AI tools are invisible1 distinct publisher
product
Apple's Business Manager API does the work; its roles model is what breaks deployments1 distinct publisher
product
Apple tells regulators it may collect nothing on third-party store sales1 distinct publisher
product
Parallels ships OpenGL 4.3 on Apple silicon, and the fleet question moves to which chip you own1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Secondhand on the part that stings
Everything reaches readers through one 9to5Mac column. Apple's confirmation of the cap is reported rather than quoted, and the limit itself is never given as a number. The Bynario detail is credited to the Financial Times, so the single case that makes the policy look heavy-handed arrives at one remove, with neither the firm nor Apple speaking to it. The Coldcard figures carry no attribution at all.
Live since June, one enforcement on record
This is a shipped policy, not a proposal: Apple set it in June and a named firm has already been locked out of the portal. Scale is where the record runs out. There is no count of researchers who have hit the ceiling, no figure for how often larger quotas are approved, and no sign of whether Apple's inbound volume actually fell. The November patch from Bynario's earlier filings shows the pipeline delivering fixes before the cap started biting.
Coldcard is asked to prove more than it can
The most persuasive passage in the column, a $116 million drain traced to a five-year-old randomness bug, is doing work the evidence does not license. Chambers says outright that he believes AI tooling was probably involved in surfacing the flaw and then allows that it may not be the full story, and the drain has no connection to Apple's portal either way. Apple's half of the framing is just as unmeasured, with no count of AI-generated reports behind the word 'flood'. The narrower, well-supported point is that a firm filing under seven reports a year got caught by an anti-slop control.
A sponsored column telling Apple to staff up
Apple @ Work opens and closes with paid copy for Mosyle, which sells Apple fleet management to exactly the readers being told Apple's triage is inadequate; the sponsorship is disclosed at both ends, which is the reason it is visible at all. Chambers writes as a working Apple administrator, so his stake is in a disclosure channel that stays wide open. Apple's own incentive runs the other way, toward describing report volume as an industry burden rather than a resourcing decision it made.
Solid on the rule, soft on the consequences
The cap and the 30-day cool-down are firm enough to act on, since Apple confirmed both. Below that, confidence thins quickly: the Bynario case is credible but borrowed, the AI-behind-Coldcard thread is explicitly inference, and the cap's numeric threshold is unknown. Independent reporting on how many researchers have hit the limit, or an Apple figure for machine-generated submissions, would move this substantially.