9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.

Apple dropped a staggering number of vulnerability patches in macOS Tahoe 26.6 last month. Plus a heap of fixes in iOS 26.6 and iPadOS 26.6. What stood out most to me was the number of credits that went to Claude, Codex, and other AI-adjacent tools and labs. The most I’ve ever seen in a single release.

Then came this week when Apple confirmed that it has capped the number of vulnerability reports a researcher can have open at once, with a 30-day cool-off period once that cap is reached.

On the surface, it looks like Apple got caught flat-footed here and started throwing up walls. It even admitted to “the growing volume of AI-generated security submissions across the industry” in its statement to the Financial Times.

However, it’s now increasingly clear that, since last year, nearly all of Apple’s rather baffling decisions around its security bug bounty program have been in preparation for this exact problem.

The changes really started in October 2025, when Apple announced what it called a “major evolution” of the Apple Security Bounty program. The headlines then boasted the program’s new $2 million top prize, which could climb north of $5 million with bonuses.

Buried in the same announcement was a new Capture the Flag-like system called Target Flags, built for bug hunters to better prove the depth of an exploit. Reports submitted with Target Flags can be processed programmatically, meaning they can be validated without a human reviewer.

For the researcher, this means a faster payday. Awards could be processed as soon as the bug is received and verified, even before a patch ships.

In hindsight, this was the first clear sign of Apple preparing for a wave of AI-generated reports. With Target Flags, it could split submissions into those that already prove their severity and those that need a human to sit down and check.

Then two months later, things got baffling when the floor fell out on a lot of low-hanging fruit. In December 2025, Csaba Fitzl, principal macOS security researcher at Iru, spotted a massive change in the allotted award amounts.

Full TCC bypasses had dropped from $30.5k to $5k. Individual TCC categories fell from the $5k to $10k range down to $1k. macOS sandbox escapes were halved to $5k. At the time, 9to5Mac verified every one of them against Apple’s own bounty categories page.

Fitzl warned that few researchers focus on the Mac to begin with, and that smaller awards would shrink that number further while raising the odds that whoever finds an exploit sells it on the black market instead of reporting it.

At the time, it baffled everyone, myself included. Apple was suddenly paying more for the incredibly rare and spectacular exploit chains and less for the everyday macOS patches that make up most of what lands in release notes.

Then June arrived with the cap on open reports and the 30-day cool-off, which apparently nobody knew about until this week, aside from the researchers who ran into it.

When piecing this timeline together and these three recent moves, two of which felt disconnected and honestly a little hostile at the time, it now clearly looks like a coordinated response.

TCC bypasses and sandbox escapes are precisely the class of bug that AI-assisted tooling (like Claude Fable) is best at surfacing right now. It’s shallow enough to find at scale, common enough to bury a triage queue, and every single one still needs a human at Apple to look at it. Paying less here and far more for the deep exploit chains that still demand real expertise, now makes way more sense.

To be clear, I don’t want to knock researchers who use AI. The 26.6 release notes are proof that these tools are finding real, exploitable, patchable bugs across Apple’s ecosystem. As I said on X, AI-assisted or not, credit where credits due. This benefits everyone.

The problem was never AI-assisted research. It’s what happens when a bounty program built around human-paced submissions meets machine output at an insane scale.

As things become clearer, I suspect this is only the beginning for the Apple Security Bounty program.

Security Bite is 9to5Mac’s weekly deep dive into the world of Apple security. Each week, Arin Waichulis unpacks new threats, privacy concerns, vulnerabilities, and more, shaping an ecosystem of over 2 billion devices. Every other week on the Security Bite Podcast, he sits down with experts in the field to break down the most pressing topics.

F ollow Arin: Twitter/X, LinkedIn, Threads