Apple、AI 生成報告の急増を受けセキュリティ報告数に制限を設ける
本文の状態
日本語全文を表示中
詳細モードで約7分の本文を読めます。
Apple はAI生成の偽報告が殺到したためセキュリティ報告数の上限を設けたが、BynarioはGPT-5.5で発見した実在バグもこの制限に阻まれ、AI活用と人的検証のバランスが業界全体で課題となっている。
AI深層分析を開く2026年8月4日 06:31
AI深層分析
キーポイント
Apple の報告数上限措置の実施
Apple は6月にAI生成の偽報告(AI slop)の急増に対応し、セキュリティ研究者が同時に保有できる調査報告数の上限を設け、超過時は30日の待機期間を課すルールを導入した。
Bynarioによる実在バグ発見と制限の衝突
BynarioはGPT-5.5を活用してmacOS Screen Sharingの深刻な脆弱性を発見したが、既に報告上限に達していたため初期報告ができず、Apple側が後から調査を再開する事態となった。
AI支援研究によるトリアージの逼迫
AIツールが数分で潜在的な欠陥を発見・記述できるようになった一方、セキュリティチームが人的に検証する速度が追いつかず、実在バグと偽報告が混在して処理能力を圧迫している。
業界全体でのAI活用と審査の課題
HackerOneも同様にAIによる一次審査(Hai Triage)を導入しているが、最終判断は人間が行うものの、AI生成報告の増加がセキュリティチームの注目を奪う構造的問題が顕在化している。
AI トリアージのリスクと人間の関与
HackerOne は最終判断は人間アナリストが行うとしているが、AI を用いた大量処理により真の脆弱性が「AI のゴミ」と誤判定されるリスクがある。
重要な引用
The company introduced the limitations in June after receiving a flood of AI-assisted reports, many of which turned out to be 'AI slop,' meaning they were not genuine vulnerabilities.
Bynario used GPT-5.5 through its Atlas platform to find more than 50 possible bugs in Apple's latest Mac operating system in just three weeks.
But submission caps don't distinguish between convincing AI-generated reports and real security flaws found with AI, causing both to compete for the attention of security teams.
HackerOne says Hai Triage does not make the final call, and all outcomes are reviewed or confirmed by human analysts, who remain responsible for deciding whether a vulnerability is real.
編集コメントを表示
編集コメント
AIがセキュリティテストを加速させる一方で、その成果物の真偽を見極める人的リソースの限界が浮き彫りになった事例である。GPT-5.5のような高性能モデルが実在バグを発見できる一方で、報告プロセス自体がボトルネックとなりかねない点は、今後のセキュリティ運用において重要な示唆となる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

Apple は現在、特定のセキュリティ研究者が同時に保有できる報告書の数を制限しています。この上限に達すると、同社の内部セキュリティポータルを通じて潜在的な危険なソフトウェア欠陥を新たに報告するまで、最大 30 日間の待機期間が必要になる可能性があります。
AI 由来の質の低い報告がセキュリティパイプラインを埋め尽くす
Apple は今年 6 月、AI を活用した多数の報告書を受け取ったことをきっかけにこの制限を導入しました。これらの報告書の多くは「AI slop(AI 由来の低品質なゴミ)」と見なされ、実際の脆弱性ではないことが判明しています。AI は研究者が潜在的な欠陥を発見し、詳細なレポートをまとめるのを支援できますが、提出された内容はすべて再現性と検証が必要となります。
イタリアのサイバーセキュリティ企業 Bynario が、この新しいルールに直面したことで注目を集めました。Financial Times の報道によると、Bynario は自社の Atlas プラットフォームを通じて GPT-5.5 を活用し、わずか 3 週間で Apple の最新 Mac OS に存在する可能性のあるバグを 50 件以上発見しました。
その発見の一つは、macOS Screen Sharing における脆弱性です。認証された VNC ユーザーが保護データにアクセスしたり、ルート権限を持つファイルを作成できたりする危険がありました。Apple はこの欠陥に CVE-2026-43760 を割り当て、macOS Tahoe 26.6 で修正を施しました。Bynario は当初、すでに Apple の同時調査上限に達していたため、この脆弱性を報告できなかったと述べています。その後、Apple は Bynario から提出されたレポートの再検討のために連絡を取りました。
Apple は、セキュリティ報告されたすべての事案を人間がレビューする方針をとっています。社内で AI を活用して大量の報告を仕分けしているものの、それでも人的チェックは不可欠です。研究者が報告数の上限に達した場合、Apple に引き上げを申請することは可能ですが、これは AI 支援による研究がいかに迅速に、人的チェックを前提としたプロセスを飽和させ得るかを示す事例です。
Apple は自社のソフトウェア脆弱性を発見するためにこの技術を社内で展開しています。最新のアップデートには、過去のリリースサイクルと比較して約 5 倍のセキュリティ修正が含まれていました。業界全体でも同様の動向が見られます。AI を活用したセキュリティツールが、プロンプトインジェクションテストからエージェントの強化まであらゆる工程を自動化し、かつては数週間かかっていた作業を数分に圧縮しています。
しかし、提出数の上限設定は、説得力のある AI 生成レポートと、AI を用いて発見された実際の脆弱性を見分けることができません。その結果、両者がセキュリティチームの注目を奪い合う状況が生まれています。
トリアージ(選別)が追いつかない
Apple はこの問題に直面している唯一の企業ではありません。バグ報奨金プラットフォームの HackerOne もすでに、"Hai Triage" というサービスを通じて、AI を活用して到着した脆弱性レポートの最初のレビューを行っています。
現在では、AI が潜在的な欠陥を特定し、セキュリティチームがそれが実在するものかどうかを判断する速度よりも速くレポートを作成できるようになっています。
HackerOne のシステムは数分でレポートを検証し、有効性の有無や追加確認の必要性を判定します。また、脆弱性の種類を分類し、深刻度を推定し、セキュリティアナリストが調査すべきか、それとも報告を却下すべきかを推奨します。
HackerOne は、AI によるトリアージ(選別)が最終判断を下すものではなく、すべての結果は人間の分析官によってレビューまたは確認され、脆弱性が実際に存在するかどうかの決定責任は依然として人間にあると述べています。
こうした AI 駆動型ワークフローの実行コストが急速に低下しているため、報告数の増加がデフォルトとなり、トリアージのボトルネックをさらに加速させています。AI を活用してこれらの報告を仕分けることでバックログ解消に寄与する可能性はありますが、システムが脆弱性を「AI によるゴミ(AI slop)」と誤認すれば、かえって重要な脆弱性が埋もれてしまうリスクもあります。
過去に実在するバグを発見してきた実績を持つ研究者にはより多くの報告を許可し、AI を利用する研究者には脆弱性の再現可能性を実証するよう求めるべきです。Apple はすでに、影響を受けるソフトウェアのバージョン、問題の再現手順、概念実証(PoC)またはエクスプロイトコードの提出を求めています。こうした基準がないまま制限を設ければ、正当な報告が却下される一方で、説得力がありながら実際には誤りである報告は止まらないという皮肉な結果になりかねません。
Apple のセキュリティ報奨金ガイドラインでは、AI によって発見された検証不足の理論的な欠陥など、不適切な報告を繰り返す研究者に対しては、180 日間の報告停止措置が科される可能性があると警告しています。また、この停止措置を 2 回以上受けた研究者は、プログラムから永久に排除される可能性があります。
過去に実在するバグを発見してきた実績を持つ研究者にはより多くの報告を許可し、AI を利用する研究者には脆弱性の再現可能性を実証するよう求めるべきです。
実際、真のバグの発見がすでに遅延している状況にあります。
Apple は過去、実際の報告に対して対応が遅れる傾向がありました。EasyOptOuts の共同創業者である Tyler Murphy 氏は、2025 年 6 月に Apple の「メールを隠す」機能に欠陥があることを同社に初めて報告しました。このバグは、本来保護すべき実在のメールアドレスが露出する恐れがありました。Apple と 1 年間やり取りが続いた末、Murphy 氏はこの問題を公にしました。
Apple は 2026 年 7 月 3 日にパッチを適用し、脆弱性を完全に解決したと発表しています。しかし、AppleInsider が同年 7 月 17 日(Apple の修正発表から 2 週間後)にその挙動を再現することに成功しました。EasyOptOuts はその後、脆弱性は修正されたと述べていますが、パッチが機能する前に露出していたアドレスはメール記録に残り続ける可能性があります。
報告数の制限がリスクを生む
今回の欠陥は、現在の AI 支援による報告の波には含まれていませんが、提出数を制限すること自体がいかに危険かを示しています。AI が報告件数を急増させる以前から、セキュリティチームは実際の脆弱性の調査と修正に苦労していました。
Apple の AI への取り組みはセキュリティに限られません。同社は最近、Safari を AI エージェントが制御できるプラットフォームへと転換しました。これは、製品インフラに AI を統合する際の考え方の転換を浮き彫りにしています。この野望こそが、セキュリティパイプラインの問題をより切迫させています。Apple が AI 駆動のインターフェースをさらに増やすほど、そこから生じる脆弱性報告にも対応し続けなければならないからです。
セキュリティチームは、AI によって報告件数が急増する以前から、実際の脆弱性の調査と修正に苦労していました。
Apple と Bynario は、GPT-5.5 が実際の macOS のバグを発見した点で合意しているが、報告の制限を巡っては意見が対立している。
原文を表示

Apple now caps how many security reports some researchers can have open at once. And once they hit that cap, they may have to wait 30 days before reporting another potentially dangerous software flaw through the company’s internal security portal.
AI slop floods security pipeline
The company introduced the limitations in June after receiving a flood of AI-assisted reports, many of which turned out to be “AI slop,” meaning they were not genuine vulnerabilities. Although AI can help researchers find possible flaws and compile detailed reports, each submission still has to be reproduced and verified.
Italian cybersecurity company Bynario drew attention to the new rules after it reached the limit. According to reporting from the Financial Times, Bynario used GPT-5.5 through its Atlas platform to find more than 50 possible bugs in Apple’s latest Mac operating system in just three weeks.
One of those findings was a flaw in macOS Screen Sharing that could allow an authenticated VNC user to access protected data and create files with root privileges. Apple assigned it CVE-2026-43760 and fixed it in macOS Tahoe 26.6. Bynario said it couldn’t report the flaw at first because it had already hit Apple’s limit for open investigations. Apple has since reached out to Bynario to review its reports.
A human reviews every security issue reported to Apple, even though the company uses AI to help sort reports when there are too many. If researchers hit the cap, they can ask Apple to raise it. But this shows how quickly AI-assisted research can flood a process that relies on people to check each report.
Apple has deployed the technology internally to find vulnerabilities in its own software. Its latest updates contained about five times as many security fixes as previous release cycles. The same dynamic is playing out across the industry: AI-powered security tools are automating everything from prompt injection testing to agent hardening, compressing work that once took weeks into minutes.
But submission caps don’t distinguish between convincing AI-generated reports and real security flaws found with AI, causing both to compete for the attention of security teams.
Triage can’t keep up
Apple isn’t the only company dealing with this issue. Bug bounty platform HackerOne already uses AI to conduct the first review of incoming vulnerability reports through a service called Hai Triage.
AI can now uncover possible flaws and write them up faster than security teams can determine whether they’re real.
HackerOne’s system reviews a report in minutes and decides if it’s likely valid, invalid, or needs additional checking. It can sort the type of vulnerability, suggest how serious it is, and recommend whether a security analyst should examine it or the report should be closed.
HackerOne says Hai Triage does not make the final call, and all outcomes are reviewed or confirmed by human analysts, who remain responsible for deciding whether a vulnerability is real.
The cost of running these AI-driven workflows is falling fast enough that volume is becoming the default, which only accelerates the triage bottleneck. Using AI to sort these reports could help clear the backlog, but it could also bury a vulnerability if the system mistakes it for “AI slop.”
Researchers with a track record of finding real bugs could be allowed to submit more, while those using AI could be asked to prove the flaw can be reproduced. Apple already asks for affected software versions, steps to reproduce the issue, and a proof of concept or exploit. Without that reference point, the cap could hold up legitimate reports while doing little to stop convincing ones that turn out to be wrong.
Apple’s Security Bounty guidelines warn that researchers who repeatedly submit ineligible reports, including theoretical flaws discovered by AI without proper validation, may have their reports paused for 180 days. Researchers with more than two paused periods may be removed from the program permanently.
Researchers with a track record of finding real bugs could be allowed to submit more, while those using AI could be asked to prove the flaw can be reproduced.
Real bugs already delayed
Apple has been slow to respond to real reports in the past. EasyOptOuts co-founder Tyler Murphy first told the company about a flaw in Apple’s Hide My Email feature in June 2025. The bug could expose the real email addresses the feature was meant to protect. After a year of back-and-forth with Apple, Murphy made the issue public.
Apple said it deployed a patch on July 3, 2026, and fully resolved the vulnerability. However, AppleInsider reproduced the behavior on July 17, two weeks after Apple’s claimed fix. EasyOptOuts has since said the vulnerability is fixed, although addresses exposed before the working patch could remain in email records.
Blunt caps risk real research
That flaw wasn’t part of the current wave of AI-assisted reports, but it shows why limiting submissions alone can be risky. Security teams were already having trouble investigating and fixing real vulnerabilities before AI caused the number of reports to jump.
Apple’s approach to AI extends beyond security. The company recently turned Safari into a platform AI agents can control, which highlights the shift in how it integrates AI into its product infrastructure. That ambition makes the security pipeline problem more urgent: as Apple builds more AI-driven surfaces, it also needs to keep up with the vulnerability reports they attract.
Security teams were already having trouble investigating and fixing real vulnerabilities before AI caused the number of reports to jump.
The post Apple and Bynario agree GPT-5.5 found a real macOS bug. They disagree on the report cap. appeared first on The New Stack.
同じ出来事を2媒体で確認
同じ出来事を扱う別媒体の記事です。見出しと公開時刻を比較できます。
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み