Implementation · Apple Private Cloud Compute

Sources

On this page
  1. CApple Security Engineering and Architecture (SEAR) (2024). Private Cloud Compute: A new frontier for AI privacy in the cloud. Apple Security Research blog. Source recordSupports: design goals, Apple silicon servers, signed trust cache, integrity protection of code and model assets, device-side attestation check against the transparency log, publication of images, threat model with physical attackers (provider-reported)
  2. CApple Security Engineering and Architecture (SEAR) (2024). Security research on Private Cloud Compute. Apple Security Research blog. Source recordSupports: Virtual Research Environment, published source components and licence, bounty (provider-reported)
  3. CApple Security Engineering and Architecture (SEAR) (2026). Expanding Private Cloud Compute. Apple Security Research blog. Source recordSupports: Google Cloud deployment with NVIDIA confidential computing, Intel TDX and Titan; two roots of trust; protections ramped up during a summer preview; research mode on live nodes (provider-reported)
  4. AY. Dittmar et al. (2026). Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence. Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '26). Source recordSupports: independent reverse engineering of the client; queries to the production service; no reproducible builds or symbols; request-token flaws; Apple's documentation-only response; no third-party API at the time of the study · abstract; §3; limitations
  5. CD. Selmanaj (2026). Beyond Prompt Injection: Hacking Apple's Private Cloud Compute. Sentry blog. Source recordSupports: independent finding that a tampered node passed attestation; metadata exposure; bounty
  6. BApple (CVE Numbering Authority) (2026). CVE-2026-20685 (Apple Private Cloud Compute Server Software). CVE Program. Source recordSupports: CVE description, affected versions and fix (vendor-assigned)
  7. AJ. Chuang et al. (2026). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. 2026 IEEE Symposium on Security and Privacy (SP). Source recordSupports: independent forgery of Intel TDX attestations and H100 attestation relay · Abstract; §1.1; §8.3
  8. BApple (2026). Private Cloud Compute (Apple Developer). Apple Developer. Source recordSupports: third-party developer access to PCC: eligibility and entitlement (provider-reported)
  9. AJ. De Meulemeester et al. (2026). DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes. 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26). Source recordSupports: independent forgery of TDX attestation reports with a DDR5 interposer · Abstract; case studies

Search

Full search page