A Milan-based startup says it discovered a serious macOS vulnerability with help from ChatGPT, but was unable to submit the report to Apple because of the company’s new cap on vulnerability submissions. According to Decrypt, the flaw was described as a full-takeover exploit and may have qualified for a bounty worth up to $200,000.
The episode matters because it highlights a growing tension in security research: AI tools can help researchers find more bugs, but they can also flood companies with low-quality reports. Apple’s apparent attempt to limit that volume may have had an unintended consequence if a legitimate, high-severity vulnerability could not be filed through the normal process.
Decrypt reported that the startup, based in Milan, found the issue using ChatGPT and then ran into Apple’s submission limit before it could formally disclose the exploit. The source material does not state whether Apple verified the flaw, paid a bounty, or changed the cap after the incident.
For users and companies, the case is a reminder that software security increasingly depends not only on finding vulnerabilities, but also on clear reporting channels that can separate meaningful discoveries from AI-generated noise. As AI-assisted research becomes more common, bug bounty programs may face pressure to adapt without blocking credible reports.
The incident also carries relevance for the crypto ecosystem, where macOS devices are widely used by developers, traders, and teams handling sensitive keys or infrastructure access. A full-device compromise, if confirmed, would be especially concerning for anyone relying on endpoint security to protect wallets, credentials, or development environments.