By Interestana AI Editorial — AI-drafted, human-overseen. How we report
macOS Exploit Unreported Due to Apple's AI Submission Cap

A Milan-based startup, known for its AI security research, has identified a critical vulnerability within Apple's macOS operating system that could grant attackers full system control. The exploit was reportedly developed using artificial intelligence tools, specifically referencing ChatGPT, to uncover the flaw. However, the startup encountered a significant obstacle when attempting to report the vulnerability to Apple: the company's new submission cap for AI-generated content. This cap, implemented by Apple, prevented the startup from formally submitting their findings through the standard security disclosure channels. The vulnerability, described as a "full-takeover flaw," means an attacker could potentially gain complete administrative access to a compromised macOS device. The startup has stated that the exploit is worth approximately $200,000 on the open market, indicating its high severity and value to malicious actors. The inability to report this critical security issue through Apple's official channels raises concerns about the effectiveness of the company's vulnerability disclosure program, particularly in an era where AI is increasingly used in both offensive and defensive cybersecurity research. The startup's predicament highlights a potential unintended consequence of Apple's AI content policies, which may inadvertently hinder the reporting of legitimate security threats. Without a formal channel to disclose the exploit, the vulnerability remains unpatched and potentially exposed to exploitation. The startup has not publicly disclosed the specific nature of the exploit or the exact AI tools used beyond mentioning ChatGPT, likely to avoid further complications or to protect their intellectual property. The incident underscores the evolving landscape of cybersecurity, where AI plays a dual role in discovering and potentially exploiting system weaknesses. Apple's decision to implement submission caps for AI-generated content, while perhaps intended to manage the volume of submissions or ensure human oversight, has in this instance created a barrier for security researchers. This situation could leave users of macOS vulnerable to attacks that might have otherwise been prevented. The startup's claim of a $200,000 valuation for the exploit suggests it is a sophisticated and valuable discovery, making its unaddressed status a significant security concern for Apple users worldwide. The company's standard procedure for reporting security vulnerabilities typically involves a dedicated portal or email address, but the AI content policy appears to have created an unexpected hurdle in this specific case. Further details regarding the specific AI models or techniques employed by the startup to discover the macOS exploit remain undisclosed.
Original source — read the full reporting at the publisher:
Read on DecryptGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.