Skip to content

Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage

Cybersecuritynews •Abinaya • August 10, 2026

CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server. Sentry Security researcher Drinor received a $150,000 Apple Security Bounty for discovering and reporting CVE-2026-20685, a flaw that could expose sensitive data […]

Extracted Entities