blog.sentry.security
Apple PCC Vulnerability Allows Root File Writes and Data Leakage
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A path traversal vulnerability, CVE-2026-20685, has been discovered in Apple's Private Cloud Compute (PCC), enabling attackers to write files as root during node boot and potentially leak sensitive AI inference telemetry. The flaw affects Apple's cloud-inference infrastructure, which is critical for AI applications. Security researcher Drinor Selmanaj reported the vulnerability and received a $150,000 bounty from Apple. The vulnerability was publicly disclosed on August 10, 2026, along with a proof of concept (PoC). Apple has addressed the issue in PCC Release 5E290.3 and later. The vulnerability poses a significant risk to data integrity and confidentiality in cloud environments. Users of the affected systems are advised to update to the latest release to mitigate risks.
Key Points: • CVE-2026-20685 allows root file writes and telemetry leakage in Apple PCC. • Drinor Selmanaj received a $150,000 bounty for discovering the vulnerability. • Apple has released a patch in PCC Release 5E290.3 to address the flaw.