Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-20685] Beyond Prompt Injection: Hacking Apple's Private Cloud Compute

Summary

Sentry researcher Drinor earned a $150,000 bounty for CVE-2026-20685, a path traversal in darwin-init that allowed root file writes on Apple's Private Cloud Compute and redirection of node telemetry.
Published
Collected

original ↗

Related coverage

back