Implementation · Apple Private Cloud Compute

Tampered node configuration passed attestation

On this page

← All known flaws

SignificantDemonstrated attackMitigatedDirect evidence

Evidence scope

Demonstrated in Apple's Virtual Research Environment, not reported as exploitation of production PCC. Significant for configuration integrity, and mitigated by Apple's path-validation fix 5 6.

Working in Apple's Virtual Research Environment, an independent researcher used a path traversal in darwin-init, which unpacks software archives when a node boots, to write files as root that survived the node's userspace reboot. The change redirected a logging daemon's telemetry and exposed per-request metadata such as token counts and timings. The researcher reports that Apple's attestation verifier treated the tampered node and a clean one identically. The researcher concludes that attestation appears to measure the installed software but not the writable configuration files that drive daemons at runtime 5. Apple's CVE record describes an attacker in a privileged network position and a fix through improved path validation, in releases from 5E290.3 6.

Sources: [5] · [6]

Search

Full search page