Field note
The Decoder's report is a useful warning about AI slop in a place where noise has real security cost: vulnerability disclosure.
The story describes a serious macOS flaw that reportedly could have qualified for a large Apple bounty, but the researcher did not submit it because the bug-bounty channel was overwhelmed by low-quality AI-generated reports. The precise bounty politics are secondary. The durable issue is queue quality.
AI-assisted reporting lowers the cost of filing plausible-looking security claims. That helps when it carries evidence, reproduction steps, and scope. It hurts when intake systems cannot separate real exploit chains from generated sludge quickly enough. The product lesson is blunt: any AI-amplified submission channel now needs provenance, dedupe, reproducibility checks, and reviewer backpressure, not just a bigger inbox.
