Skip to content
Attack on Apple's Private Cloud Compute: $150,000 for Security Researcher

Attack on Apple's Private Cloud Compute: $150,000 for Security Researcher

Heise.De • August 10, 2026

Apple has paid a six-figure sum to a security researcher who managed to get its AI inference environment Private Cloud Compute (PCC) to leak sensitive data. The vulnerability, with CVE ID 2026-20685, allows for a leak of telemetry information from one of the servers used to perform more complex tasks as part of Apple Intelligence . The problem was discovered and reported by Drinor Selmanaj from the security company Sentry.

Apple's bug bounty program was expanded in 2024 with various tiers for finding vulnerabilities in PCC . There are a total of five different tiers: $50,000 for random or unexpected data exfiltration due to deployment or configuration errors, $100,000 for executing non-certified code, and $150,000 for the exfiltration of user request data or other sensitive information from the “Trust Boundary”. Selmanaj reached the latter tier. Two further tiers (extension of the aforementioned tier with more data, execution of arbitrary code) are endowed with $250,000 and one million dollars, respectively.

CVE-2026-20685 allowed an attacker, via path traversal in the code of Apple's darwin-init routine, to redirect telemetry data of the inference, i.e., the output of the PCC server, to their own server – although this only seems to work if the attacker is in a privileged network position (i.e., in the same network).

Prompt and answer text, as well as token IDs or token strings, did not leak in the attack, but the number of input and output tokens, the number of draft output tokens, the number of user tokens, and latency and output times did. All of this could be used for fingerprinting.

According to Sentry, the security vulnerability itself is very old – similar bugs existed 30 years ago. Selmanaj used Apple's Virtual Research Environment (VRE) for the research, which allows security experts to find and test PCC vulnerabilities. Apple Intelligence's production infrastructure is not used for this.

Mit Ihrer Zustimmung wird hier ein externer Preisvergleich (heise Preisvergleich) geladen.

Ich bin damit einverstanden, dass mir externe Inhalte angezeigt werden. Damit können personenbezogene Daten an Drittplattformen (heise Preisvergleich) übermittelt werden. Mehr dazu in unserer Datenschutzerklärung .

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Companies (1)

CWE Weaknesses (1)

Domains (1)