苹果赏金邮箱被AI垃圾报告挤爆,意大利团队发现了个值20万美元的真macOS漏洞,差点没报上去。
苹果漏洞赏金计划正被AI生成的报告淹没,已限制每位研究者的提交数量。意大利初创公司Bynario发现的一个严重macOS漏洞,因苹果收件箱被假报告塞满而一度无法提交。该漏洞在黑市上价值最高达20万美元。AI捏造的无效报告正在堵塞人工审查管道。
A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
Apple's bug bounty program is drowning in AI-generated bug reports. The company has capped submissions per researcher because fabricated reports are clogging the review pipeline. As a result, Italian startup Bynario was initially unable to report a serious macOS vulnerability worth up to $200,000 on the black market. The article A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop appeared first on The Decoder .
- IT之家06:09原文