Source · Tier C · Blog / article
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
D. Selmanaj. 2026. Sentry blog.
See what cites it| Link | https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/ |
|---|---|
| Accessed | 2026-09-24 |
| Note | Independent researcher's write-up of CVE-2026-20685, found in Apple's Virtual Research Environment: a path traversal in darwin-init's cryptex extraction gave root file writes that survived the node's userspace reboot and redirected splunkloggingd telemetry, exposing per-request metadata such as token counts and timings (the post does not say whether prompt or response content was exposed). All work was done in the VRE. States that the tampered node was indistinguishable from a clean one under `pccvre attestation verify`, and that Apple paid a $150,000 bounty. |