• Sources: report, discussion
  • Summary: the-decoder, in a piece dated 2026-08-02 summarizing a Financial Times story, reports that Apple has capped bug bounty submissions per researcher with a 30-day cooldown because of AI-generated report volume, and that researchers can request a higher quota. The same summary states that a macOS privilege flaw held by the Italian startup Bynario went unfiled under the cap, that Bynario CEO Alfredo Pesoli put its black-market value in a 100,000 to 200,000 dollar range, and that Apple has since reached out to Bynario. No affected or fixed macOS version is named for that flaw, so the affected versions are not known from this sourcing. The Financial Times original was not reachable from this run, so every detail here rests on the secondary summary rather than the primary report.
  • Why it matters: The slop problem that polluted the CVE pipeline is now rate-limiting a major vendor's intake, with the delayed filing of a reported real vulnerability as the cost.
  • Follow-up: Confirm the submission cap against Apple's own security research pages or the Financial Times original.

send feedback on this story