The number that matters is 50: macOS bugs that one Italian security startup, Bynario, found in three weeks using ChatGPT, one of them a privilege-escalation exploit that would give an attacker full control of a Mac, valued at up to $200,000 on the black market and potentially eligible for Apple's top reward of $2 million. The bug that mattered could not be reported, because in June Apple had quietly capped the program: researchers no longer get unlimited open reports in the security portal, and hitting the limit starts a 30-day cooldown, with increases available on request but not automatically. The Financial Times surfaced the change, followed by MacRumors, Engadget and 9to5Mac; Bynario's case is the one that made it legible.

The cause is the same curve this newsroom tracked in Chrome's record June and in Microsoft's patch backlog: AI-assisted analysis now finds real vulnerabilities faster than humans can validate them, and validation is the part that cannot be hired quickly, because it takes senior engineers to tell a real exploit from a confident hallucination. Sophos's Rafe Pilling put the inversion in one line: bug bounty programs have gone from finding vulnerabilities to validating them at machine speed. Apple is on both sides of the curve at once, which is the detail worth pausing on. Its latest system update, iOS 26.6, fixed nearly 90 vulnerabilities, some credited to Anthropic's Claude and OpenAI's Codex Security, and Apple has deployed its own AI system to triage incoming reports, separating legitimate bugs from the AI slop the same tools generate.

The failure mode that should worry every program owner is not the volume, it is the block: a critical, black-market-valuable vulnerability sat unreported because a quota stopped a legitimate researcher who did not know the quota existed. After the case became public, Apple contacted Bynario and is reviewing its submissions, so that particular bug reaches the security team. GitHub, facing the same flood, made its payouts less generous for low and medium severity bugs; Google and Microsoft are confronting the same volume in parallel. No major program has answered the underlying question, which is how to pay for validation at the speed finding now runs.

For the people inside this story, the practical notes are plain. If you run a bounty program, a quota you do not publicize will block exactly the report you most want, so the request-an-increase path has to be loud, not documented. If you research with AI tools, expect every major program to add caps and triage, and price that into your pipeline. And for everyone else: the same week that AI found a 13-year-old bug in Chrome, it also drowned the world's most generous bounty program. Both sentences are true, and the second one is the newer news.