A Milan-based security startup has stumbled upon a critical macOS vulnerability that could grant attackers full system control — and then discovered that Apple’s new submission cap left them unable to report it. The firm says it used ChatGPT to help uncover the flaw, which they believe is worth up to $200,000 under Apple’s bug bounty program, but the tech giant’s recently introduced daily report limit slammed the door on their disclosure.

How ChatGPT Helped Find a Full-Takeover Flaw

The researchers, who asked to remain unnamed, told Decrypt that they leveraged OpenAI’s ChatGPT to analyze suspicious code patterns in macOS. By feeding the AI model snippets of system libraries and asking it to identify potential memory corruption points, the team quickly zeroed in on a privilege escalation vector that could let an attacker execute arbitrary code with kernel-level permissions.

“We were honestly surprised how fast it worked,” one researcher said. “Within a few hours, ChatGPT pointed us to a specific function call that looked off. We manually verified it and realized we had a full chain — from a sandboxed app to root.” The flaw, they claim, could be exploited remotely if combined with a browser vulnerability, making it a severe threat to Mac users.

Apple’s New Submission Cap Blocks Critical Disclosure

But the excitement of the find quickly turned to frustration. Apple rolled out a new policy in late July that limits researchers to a certain number of bug bounty submissions per day — a move aimed at reducing noise from low-quality reports. The Milan team, however, hit that cap before they could file their critical finding.

“We tried to submit, but the portal said we’ve reached our daily limit,” the researcher explained. “We couldn’t wait 24 hours because the vulnerability could be exploited in the wild at any moment. We had to go public with our findings to put pressure on Apple.”

Apple has not yet responded to requests for comment. Security experts say the cap is a double-edged sword: it filters out spam but can also delay urgent reports, potentially leaving users exposed for longer than necessary.

The $200K Question

Under Apple’s Security Bounty program, a full chain that compromises a Mac without user interaction can earn a researcher up to $200,000. The Milan startup believes their discovery qualifies for the top tier, but with the submission blocked, that payout is now in limbo. “We’re not doing this for the money, but it would be nice to be compensated fairly,” the researcher added.

What This Means for Mac Users

For the average Mac user, the practical risk is still low — there’s no evidence the flaw has been exploited in the wild yet. However, the incident highlights a growing tension in the security research community: AI tools like ChatGPT are making it easier to find bugs, but the reporting pipeline is struggling to keep up.

  • Immediate risk: Low, but update macOS to the latest version if available.
  • Long-term concern: Submission caps may discourage researchers from reporting serious issues.
  • AI in security: Expect more AI-assisted vulnerability discoveries, both by good guys and bad actors.

Apple’s bug bounty program has historically been generous, but the new cap could backfire. Security researchers are already discussing alternatives, including selling the exploit to brokers or publishing it publicly — neither of which helps Apple or its users.

Key Takeaways

This story is a wake-up call for Apple: policy changes that aim to reduce noise can inadvertently silence the most important signals. The Milan startup’s decision to go public is a bold move that will likely force Apple to reconsider its submission limits. In the meantime, Mac users should stay vigilant, apply patches promptly, and hope that this exploit doesn’t find its way into the wrong hands before Apple can fix it.

For security researchers, the lesson is clear: AI is a powerful ally, but the human element — and the bureaucratic hurdles around it — remains the biggest bottleneck.