Apple’s security team has a new adversary, and it’s not a shadowy hacking group. It’s the sheer volume of vulnerability reports generated by researchers wielding AI tools, a problem the Financial Times calls a growing crisis for corporate bug bounty programs.
As of November 2025, Apple raised its top Security Bounty payout to $2 million for sophisticated zero-click exploit chains. With potential bonuses, individual payouts can exceed $5 million.
Apple has also expanded its bounty categories and rolled out a systematic flagging mechanism designed to speed up the validation process. Since launching its bounty program, Apple has paid out more than $35 million to over 800 researchers.
The same large language models that help skilled researchers automate tedious parts of vulnerability analysis also let less skilled operators blast out hundreds of superficially plausible but ultimately useless reports. Bug bounty administrators now face a triage nightmare. Every submission needs human review to determine if it’s a genuine zero-day or just an AI hallucination dressed up in technical jargon.
This isn’t unique to Apple. The FT’s reporting suggests it’s an industry-wide phenomenon affecting corporate bounty programs broadly.
AI tools are genuinely accelerating the discovery of complex vulnerabilities. But the operational burden of processing AI-assisted findings is threatening to overwhelm the very programs designed to incentivize that discovery.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
22









English (US) ·