Security Bite: Apple’s baffling bug bounty changes finally make sense

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
Apple dropped a staggering number of vulnerability patches in macOS Tahoe 26.6 last month. Plus a heap of fixes in iOS 26.6 and iPadOS 26.6. What stood out most to me was the number of credits that went to Claude, Codex, and other AI-adjacent tools and labs. The most I’ve ever seen in a single release.
Then came this week when Apple confirmed that it has capped the number of vulnerability reports a researcher can have open at once, with a 30-day cool-off period once that cap is reached.
On the surface, it looks like Apple got caught flat-footed here and started throwing up walls. It even admitted to “the growing volume of AI-generated security submissions across the industry” in its statement to the Financial Times.
However, it’s now increasingly clear that, since last year, nearly all of Apple’s rather baffling decisions around its security bug bounty program have been in preparation for this exact problem.
Related Markets
All MarketsMarket data may be delayed. Not financial advice.
💡 AI analysis provides alternative perspectives on current events