Apple’s Submission Cap Reportedly Delayed a $200K macOS Exploit Report

A Milan startup says it used ChatGPT to identify a macOS vulnerability that could enable full system takeover. The company claims Apple’s new submission cap stopped it from reporting the flaw before the issue became public.

Apple’s Submission Cap Reportedly Delayed a $200K macOS Exploit Report

What happened?

A Milan startup says it used ChatGPT to identify a macOS vulnerability that could enable full system takeover. The company claims Apple’s new submission cap stopped it from reporting the flaw before the issue became public.

Why it matters

A Milan-based startup says it discovered a serious macOS vulnerability with help from ChatGPT, but was unable to submit the report to Apple because of the company’s new cap on vulnerability submissions. According to Decrypt, the flaw was described as a full-takeover exploit and may have qualified for a bounty worth up to $200,000.

A Milan-based startup says it discovered a serious macOS vulnerability with help from ChatGPT, but was unable to submit the report to Apple because of the company’s new cap on vulnerability submissions. According to Decrypt, the flaw was described as a full-takeover exploit and may have qualified for a bounty worth up to $200,000.

The episode matters because it highlights a growing tension in security research: AI tools can help researchers find more bugs, but they can also flood companies with low-quality reports. Apple’s apparent attempt to limit that volume may have had an unintended consequence if a legitimate, high-severity vulnerability could not be filed through the normal process.

Decrypt reported that the startup, based in Milan, found the issue using ChatGPT and then ran into Apple’s submission limit before it could formally disclose the exploit. The source material does not state whether Apple verified the flaw, paid a bounty, or changed the cap after the incident.

For users and companies, the case is a reminder that software security increasingly depends not only on finding vulnerabilities, but also on clear reporting channels that can separate meaningful discoveries from AI-generated noise. As AI-assisted research becomes more common, bug bounty programs may face pressure to adapt without blocking credible reports.

The incident also carries relevance for the crypto ecosystem, where macOS devices are widely used by developers, traders, and teams handling sensitive keys or infrastructure access. A full-device compromise, if confirmed, would be especially concerning for anyone relying on endpoint security to protect wallets, credentials, or development environments.

Source: Decrypt

Keep exploring

Related stories

Tether Gold Reserves Rise 9.5% During Gold’s Sharpest Quarterly Drop Since 2013

Tether Gold Reserves Rise 9.5% During Gold’s Sharpest Quarterly Drop Since 2013

Tether Gold increased its bullion backing by 9.5% in the second quarter, even as gold recorded its steepest quarterly correction in 13 years. The move came alongside continued growth in holder counts for tokenized commodities.

Read
Strategy Sells $104M in Bitcoin to Support STRC

Strategy Sells $104M in Bitcoin to Support STRC

Strategy sold $104 million worth of Bitcoin last week to help support STRC. The move stands out because STRC is described as a financial product designed to help the company buy more Bitcoin.

Read
Texas ERCOT Data Center Pause Not Expected to Hit Approved Bitcoin Miner Power Deals

Texas ERCOT Data Center Pause Not Expected to Hit Approved Bitcoin Miner Power Deals

Bernstein said Texas Governor Greg Abbott’s moratorium on approvals for ERCOT-linked data centers is not expected to materially affect Bitcoin miners with already approved electricity contracts. The pause applies while an audit is pending, according to the source material.

Read