Heise.De Apple's Private Cloud Compute Vulnerability Exposes Sensitive Data
Article Content
- •CVE-2026-20685 allows root file writes and telemetry leakage in Apple's PCC.
- •Drinor Selmanaj received a $150,000 bounty for discovering the vulnerability.
- •The flaw affects AI inference processes and requires privileged network access for exploitation.
A path traversal vulnerability (CVE-2026-20685) in Apple's Private Cloud Compute (PCC) was discovered by security researcher Drinor Selmanaj, leading to a $150,000 bounty. The flaw allows attackers in a privileged network position to write files as root during node boot and redirect AI inference telemetry to an external server. Although sensitive data such as prompt and answer text did not leak, telemetry information including token counts and latency data was exposed, which could aid in fingerprinting users. The vulnerability was reported through Apple's Virtual Research Environment, which is designed for security testing. Apple has since addressed the issue in PCC Release 5E290.3 and later. This incident highlights the importance of security in AI-driven environments, especially those handling sensitive user data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Apple and CVE-2007-4559 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
GitSpawn Vulnerabilities Allow Code Execution in AI Coding Agents A series of vulnerabilities, termed GitSpawn, have been disclosed affecting multiple AI coding agents, including Claude Code, Codex, and Cursor. These flaws allow malicious Git configurations to execute arbitrary code on a developer's machine without user interaction or approval. The vulnerabilities were identified by…
Zip Slip Vulnerability Exploitation via Zip File Uploads A utility script has been released to exploit the Zip Slip vulnerability, which allows attackers to extract files to unintended directories via zip file uploads. This vulnerability can lead to remote code execution by placing malicious web shells in accessible directories. The script generates zip files containing…