Skip to content
RegulationNeutral

Milan start-up uncovers $200K macOS exploit using ChatGPT, but can't report it

Source: Decrypt
Milan start-up uncovers $200K macOS exploit using ChatGPT, but can't report it

A start-up based in Milan has discovered a serious flaw in macOS that allows for a full system takeover, and the company claims that it was using ChatGPT as part of its research process. This exploit, which the start-up values at $200,000, could potentially provide malicious actors with unauthorized access to sensitive data and control over affected systems. However, the company faced a setback when it hit Apple's new submission cap, which prevented them from formally reporting the vulnerability before the deadline.

The emergence of this critical flaw highlights the ongoing security challenges faced by major tech companies like Apple. As cyber threats continue to evolve, the need for robust security measures becomes more pressing. Apple's recent implementation of a submission cap aims to streamline the process of reporting vulnerabilities, but it appears that this has inadvertently created obstacles for researchers seeking to disclose critical security issues in a timely manner. This incident raises questions about the effectiveness of such policies in fostering a secure ecosystem.

The implications of this exploit are significant for the market, particularly for users of macOS systems. With a full-takeover vulnerability, the potential for data breaches and privacy violations is heightened. This situation could lead to a decline in user trust and confidence in Apple's security measures, especially if the exploit becomes widely known or exploited by malicious actors. The incident serves as a reminder of the importance of timely vulnerability disclosure and the need for companies to adapt their policies to better support security researchers.

Industry reactions to the incident have been mixed. Some experts have expressed concern over the limitations imposed by Apple's submission cap, arguing that it may deter researchers from reporting vulnerabilities altogether. Others believe that companies need to establish clearer channels for communication and collaboration with the security community. The discourse surrounding this incident emphasizes the necessity for a balance between maintaining a secure platform and encouraging responsible vulnerability disclosure.

Looking ahead, it will be crucial for Apple to address the challenges posed by its current submission policies. The company may need to reconsider its approach to vulnerability reporting to ensure that researchers can effectively communicate their findings without facing bureaucratic hurdles. As the tech landscape continues to evolve, fostering a proactive relationship between companies and the security community will be essential in mitigating risks and enhancing overall cybersecurity.

CoinMagnetic

CoinMagnetic Team

Crypto investors since 2017. We trade with our own money and test every exchange ourselves.

Updated: August 2026

Get news first?

Follow our Telegram channel – we post the top news and analysis.

Follow the channel

Related news