Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage

CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server. Sentry Security researcher Drinor received a $150,000 Apple Security Bounty for discovering and reporting CVE-2026-20685, a flaw that could expose sensitive data […]

This article has been indexed from Cyber Security News

Read the original article: