Skip to content
Apple's Private Cloud Compute Vulnerability Exposes Sensitive Data

Apple's Private Cloud Compute Vulnerability Exposes Sensitive Data

First seen 10 Aug 2026, 14:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 11, 2026 at 13:46 UTC
  • •CVE-2026-20685 allows root file writes and telemetry leakage in Apple's PCC.
  • •Drinor Selmanaj received a $150,000 bounty for discovering the vulnerability.
  • •The flaw affects AI inference processes and requires privileged network access for exploitation.

A path traversal vulnerability (CVE-2026-20685) in Apple's Private Cloud Compute (PCC) was discovered by security researcher Drinor Selmanaj, leading to a $150,000 bounty. The flaw allows attackers in a privileged network position to write files as root during node boot and redirect AI inference telemetry to an external server. Although sensitive data such as prompt and answer text did not leak, telemetry information including token counts and latency data was exposed, which could aid in fingerprinting users. The vulnerability was reported through Apple's Virtual Research Environment, which is designed for security testing. Apple has since addressed the issue in PCC Release 5E290.3 and later. This incident highlights the importance of security in AI-driven environments, especially those handling sensitive user data.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2007-08-28
CVE-2007-4559 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-18
CVE-2026-20685 published
Apple assigned CVE-2026-20685 to a path traversal vulnerability in PCC, affecting AI inference security.
blog.sentry.security
2026-08-10
Security researcher awarded $150,000 bounty
Drinor Selmanaj was awarded for reporting the vulnerability that could leak sensitive data from PCC.
Heise.De
2026-08-10
Vulnerability details disclosed
The vulnerability allows attackers to redirect telemetry data to their own servers, exposing user information.
Cybersecuritynews
2026-08-10
Apple addresses the vulnerability
Apple released updates in PCC Release 5E290.3 and later to fix the identified flaw.
Gbhackers

More articles in this cluster (6)

Following this threat?

Track Apple and CVE-2007-4559 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed