Apple fixed CVE-2026-20685, a path traversal flaw in its Private Cloud Compute (PCC) environment that could allow an attacker to write files as root during node boot and redirect sensitive AI inference telemetry to an external server. The vulnerability was found in darwin-init, a root-privileged early boot component that extracted attacker-controlled archives without properly blocking traversal sequences, enabling writes outside the intended directory and onto PCC's writable data volume. Apple rated the issue as information disclosure with a CVSS score of 6.5 and addressed it in PCC releases 5E290.3 and later.
Research showed a crafted archive could persist across boot and modify PCC logging behavior through splunkloggingd configuration, exposing metadata tied to Apple Intelligence inference requests inside Apple's Virtual Research Environment. The work, published through Sentry's AI security research effort, also highlighted an attestation gap because files on the writable data volume that could influence runtime daemon behavior were not included in PCC attestation measurements. Sentry researcher Drinor reported the flaw and received a $150,000 Apple Security Bounty.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Apple awarded Drinor a $150,000 Security Bounty for the CVE-2026-20685 finding affecting Private Cloud Compute. The award was cited in coverage of Sentry's AI security research into Apple's privacy-focused cloud AI architecture.
Apple remediated CVE-2026-20685 in Private Cloud Compute releases 5E290.3 and later. Apple classified the issue as an information disclosure vulnerability with a CVSS score of 6.5.
Sentry Security researcher Drinor discovered and reported CVE-2026-20685, a path traversal flaw in Apple's Private Cloud Compute that could enable root file writes during node boot and redirection of AI inference telemetry. The research also identified an attestation gap involving writable data volume files that could affect runtime daemon behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceheise.de
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.