A researcher discovered a critical vulnerability in macOS worth $200,000 and reported it through proper channels. Apple never acted on it. The company's security team ignored the disclosure, and when the researcher tried following up, the response was buried under automated AI-generated summaries that missed the core issue entirely.
The flaw itself wasn't minor. It allowed attackers to escalate privileges on Mac systems, a gateway to full device compromise. Yet the security researcher's detailed technical report vanished into Apple's intake system, processed by what appears to be machine-learning summaries that flattened the severity and context.
How AI Became the Gatekeeper
Apple's security reporting program accepts vulnerability disclosures through an online portal. Reports land in a queue, get assigned to teams, and theoretically move toward patches. But somewhere in that pipeline, AI-powered tools began summarizing incoming disclosures. These summaries condensed 15-page technical analyses into bullet points, stripped out key reproduction steps, and sometimes misclassified risk levels entirely.
The researcher watched weeks pass without response. Follow-up emails hit the same wall. When they finally received acknowledgment, it was a generic template that suggested the initial report hadn't been properly reviewed by human eyes. The $200,000 bug bounty hung in limbo because the vulnerability never actually reached the engineers who could fix it.
This isn't isolated. Multiple security researchers have reported similar experiences with major tech companies rushing to deploy AI triage systems without adequate human oversight. The incentive is obvious: process more reports faster with fewer staff. The cost is real: critical vulnerabilities languish, disclosure windows close, and attackers potentially gain months of unpatched systems.
Apple eventually acknowledged the issue after escalation, but the delay raised uncomfortable questions about how companies balance automation with accountability. A $200,000 bounty suggests the company takes security seriously. Yet the machinery designed to protect users almost failed because it was optimized for speed, not accuracy.
This article is informational only and does not constitute security or investment advice. Always follow responsible disclosure practices when reporting vulnerabilities.



