by

Apple swamped with bugs

The Fruity Cargo Cult Apple has capped bug reports after AI made its software holes look more holy than St Peter’s on Easter.

According to the Financial Times, Job’s Mob has restricted how many potentially dangerous software bugs researchers can submit to its internal security team because they have been swamped.

The move follows a flood of reports from people using AI models to spot risks in its software. The Tame Apple Press insists that while some appear to have found real problems, others have sprayed Cupertino with machine-generated nonsense.

Job’s Mob told the FT it changed the rules in June because its review system was getting battered by “AI slop”. These reports can hallucinate security risks in its absolutely perfect software.

The outfit is dealing with a wider industry problem as generative AI rewires the cyber security arms race. The tools are finding genuine flaws, but they are giving amateur bug hunters a cheap way to fling low-grade reports at vendors.

Italian cyber security start-up Bynario told the FT it had used OpenAI’s ChatGPT to identify more than 50 bugs in the latest MacBook operating system in three weeks.

One was a nasty privilege escalation exploit chain which could let an attacker seize full control of a Mac by gaining unrestricted system access.

Bynario said it could not alert Job’s Mob to the vulnerability because the company had capped the number of bug reports it could make so now Apple fanboys will have to suffer if they are hacked.

Bynario chief executive and co-founder Alfredo Pesoli said: “It is a very difficult time in the industry. Maintainers and vendors have been flooded by the sheer amount of bugs being found.”

Apple told the FT it was now talking to Bynario and reviewing its submissions. Apparently, the heavenly gates can open after all if enough embarrassment builds up outside.

The company has added a cap and a 30-day cooling-off period for reports through its internal security portal. Researchers must now ask for a higher quota if they want to keep feeding in alleged breaches.

Each claimed security hole needs human review before it can be confirmed. Job’s Mob is using AI internally to help sort the incoming muck pile, which has a pleasingly circular stink to it.

Apple said: “With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once. Researchers can easily request an increase to that limit at any time to ensure critical reports reach our security teams.”

Last September, Job’s Mob announced Memory Integrity Enforcement, a feature meant to block memory corruption attacks. The company called it “the most significant upgrade to memory safety in the history of consumer operating systems”.

Eight months later, Palo Alto-based Calif said it had already found a way through the shiny new guardrail. Its researchers used Anthropic’s Mythos to identify the first memory corruption exploit on the latest software.

Bynario’s exploit relied on logic flaws, tricking trusted software into performing legitimate actions in an unintended sequence. Pesoli estimated that such an exploit could fetch between $100,000 and $200,000 on the cybercriminal black market. That is a tidy payday for finding holiness in Job’s Mob’s blessed plumbing.

 

TOPICS:
ai slop  ·  anthropic  ·  Apple  ·  bug bounty  ·  Bynario  ·  chatgpt  ·  Cyber security  ·  macos  ·  software bugs

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews