苹果因AI生成的虚假安全漏洞报告大量涌入,于8月2日对其bug赏金计划实施限制措施[1]。该公司在内部安全门户上设置了漏洞提交数量上限和30天冷静期[1],以缓解审核团队的压力。
虚假漏洞报告已成为安全行业的普遍问题[1]。根据数据预测,2026年CVE登记量将达66000个,相比原始预估高出46%[1]。Curl创始人曾透露,在前三周内收到的20份漏洞报告中,没有任何一份是真正的安全漏洞[1]。与此同时,安全研究公司Calif利用Claude在5天内绕过苹果MIE防护系统获得了root权限[1]。
面对这一困境,多家企业已调整或暂停了各自的漏洞赏金计划[1]。Google在3月宣布不再接受AI生成的漏洞报告;Nextcloud在4月暂停漏洞赏金计划;GitHub在7月大幅削减赏金额度[1]。2026年7月27日,苹果发布macOS Tahoe 26.6安全更新,修复194个漏洞,首次正式致谢Claude和Codex Security等AI工具[1]。
Apple has restricted submissions to its security vulnerability program following an overwhelming surge of artificially generated false reports. On August 2, the company implemented submission caps and a 30-day cooldown period on its internal security portal to relieve strain on its review team [1].
The problem extends beyond Apple. Security researchers have increasingly weaponized AI tools to flood bug bounty programs with fabricated vulnerabilities. Daniel Stenberg, founder of Curl, reported receiving 20 vulnerability submissions within three weeks, of which zero constituted genuine security flaws [1]. This trend has prompted multiple organizations to take action: Google announced in March that it would no longer accept AI-generated vulnerability reports, Nextcloud suspended its bounty program in April, and GitHub substantially reduced its reward amounts in July [1].
The issue gained further attention when security research firm Calif leveraged Claude to bypass Apple's MIE protection system and gain root access within five days in May 2026 [1]. Despite these challenges, Apple has also acknowledged AI's legitimate security contributions. On July 27, the company released macOS Tahoe 26.6, patching 194 vulnerabilities and marking the first instance where Apple formally credited AI tools including Claude and Codex Security in its security updates [1]. The broader impact is reflected in projections showing 2026 CVE registrations reaching 66,000—a 46 percent increase over earlier estimates [1].