Apple’s AI ‘Slop’ Problem: A $200K Exploit Went Unreported, No Cap

Date:

Heads up, tech fans! Apple, a company usually ‘on point’ with its security, has run into a legit headache: its bug reporting system is getting slammed by a massive influx of AI-generated junk, creating what many are calling an ‘AI Slop Problem’. This isn’t just a minor annoyance, dude; it’s got real consequences. According to a report by the Financial Times, this flood of bogus submissions actually led to a critical macOS exploit, valued anywhere between $100,000 and $200,000 on the black market, going completely unreported. Milan-based cybersecurity startup Bynario found a privilege escalation chain using OpenAI’s ChatGPT, a flaw that could hand an attacker ‘unrestricted control’ of a Mac machine, but couldn’t get Apple to even look at it. No cap, that’s a serious miss.

To combat this digital deluge, Apple recently put a cap on how many vulnerability reports a researcher can have open at once, and even added a 30-day cool-off period. While researchers can apply for a higher quota, the initial limit left Bynario out in the cold, unable to alert Apple to the ‘fire’ they’d uncovered. Interestingly, Apple itself is also leveraging AI internally to help triage the massive pile of incoming reports, trying to sift through the genuine threats amidst the noise. The company stated it has ‘recently adjusted the number of new reports a researcher can have open at once’ and that higher limits are available upon request. It’s a tricky balance when the very technology causing the problem is also seen as a potential part of the solution.

This ‘slop’ problem isn’t unique to Apple, though. The issue of AI bug reporting volume has highkey exploded in recent months, with other major players feeling the pinch. Security firm Bugcrowd, which works with clients like OpenAI, reported that submissions through its platform more than quadrupled over three weeks in March, with most being utterly fake. HackerOne and Nextcloud, two prominent bug bounty platforms, had to hit pause on their paid programs back in April. Nextcloud even went so far as to state that ‘no rewards would be paid regardless of severity’ until they figured out a way to filter out the low-effort, AI-generated reports. It’s a wild west out there for maintainers and vendors, who are ‘straight up’ flooded by the sheer amount of bugs, real or imagined.

But here’s where it gets interesting: while AI is churning out digital ‘slop’, it’s also becoming incredibly adept at spotting legitimate, complex vulnerabilities. In March, Anthropic introduced Mythos, a cyber-focused model initially restricted to select tech companies, banks, and researchers. Mozilla, for example, reported that Mythos surfaced an astounding 271 vulnerabilities in Firefox during its internal testing. Talk about ‘dope’ tech! Another startup, Calif, based out of Vietnam, even used a preview version of Mythos to build the ‘first public macOS kernel memory corruption exploit’ able to bypass Apple’s Memory Integrity Enforcement, a defense system Apple hailed as its ‘biggest memory safety upgrade’ in consumer operating systems. Calif delivered their findings in person to Apple’s California headquarters, specifically to avoid ‘getting buried in the submission flood,’ a move that proved savvy given Bynario’s later experience.

The dual nature of AI in cybersecurity extends beyond traditional software, making waves in the crypto space too. Coldcard wallet manufacturer Coinkite has suggested that AI was likely behind the discovery of a bug in its open-source firmware, a flaw that sat unnoticed for five years and allowed attackers to swipe over $100 million from hardware wallets. And get this: just a couple of months prior, Zcash revealed that researcher Taylor Hornby, collaborating with Claude Opus 4.8, uncovered two lines of code in its Orchard shielded pool that permitted ‘undetectable counterfeiting’ of ZEC for four years. This prompted Zcash to roll out its Ironwood upgrade to fix the vulnerability. It’s clear that AI is a double-edged sword, both an invaluable tool for defense and a potent weapon for offense in the ever-evolving landscape of digital security, and the industry is grappling with how to handle this new reality.If you enjoyed this article, share it with your friends or leave us a comment!

Comments Here
Darius Zerin
Darius Zerin
Darius Zerin specializes in business strategy, entrepreneurship, and market trends. He covers everything from startups to global finance, offering practical insights and forward-thinking analysis. His writing is designed to help readers stay ahead in a constantly evolving economic landscape.

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

Apple’s AI Bug Flood: A ‘Sketchy’ Situation for Real Exploits

Apple's security team is grappling with a wild new...

Carnival Films Snaps Up a ‘Sick’ New Murder Mystery, No Cap!

Hold onto your hats, folks, because Carnival Films, the...

Carnival Films Snaps Up Rights to Pinborough’s New Thriller: It’s Gonna Be Lit!

Hold up, crime drama fanatics! Carnival Films, the ace...

Toronto Film Festival: Auteurs Get ‘Deep’ in Wavelengths, It’s Legit

The Toronto Film Festival is about to drop some...