蘋果公司因面臨大量由人工智慧生成的虛假安全漏洞報告(所謂的「AI 垃圾」),已限制安全研究人員向其內部安全團隊提交錯誤報告的數量。這些低品質的提交是由業餘漏洞獵人使用生成式 AI 工具所產生的,給蘋果的審查系統帶來了巨大的壓力。
義大利資安新創公司 Bynario 利用 ChatGPT 在短短三週內發現了 50 多個 MacBook 作業系統的漏洞,其中包括一個嚴重的權限提升漏洞。然而,由於蘋果最近實施的提交上限和冷卻期政策,該公司無法將此重大漏洞回報給蘋果。
儘管 AI 產生了大量虛假報告,但它同時也幫助了專業研究人員發現危險的漏洞,甚至蘋果本身也利用 AI 來加強其軟體安全。這使得漏洞賞金計畫的挑戰從尋找漏洞轉變為如何以機器的速度驗證、優先處理及回應這些問題。
Apple has restricted the number of bug reports security researchers can submit to its internal team due to a flood of "AI slop" — hallucinated or low-quality security risks. These submissions, generated by amateur bug hunters using generative AI tools, have placed immense pressure on Apple's review system.
The Italian cybersecurity startup Bynario utilized ChatGPT to discover over 50 bugs in the MacBook operating system within three weeks, including a severe privilege escalation vulnerability. However, the startup was unable to report this critical flaw to Apple because they hit the newly implemented submission caps and cool-off periods.
Although AI has generated a massive volume of fake reports, it also assists skilled researchers in finding dangerous exploits, and even Apple uses AI to strengthen its own software security. This dynamic is shifting the challenge of bug bounty programs from merely finding vulnerabilities to validating, prioritizing, and responding to them at machine speed.