[CVE-2026-20685] Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
blog.sentry.security | research | CVE-2026-20685 | #ai-security | #bug-bounty | #cloud | #path-traversal | #apple | #private-cloud-compute | #cve-2026-20685
Summary
Sentry researcher Drinor earned a $150,000 bounty for CVE-2026-20685, a path traversal in darwin-init that allowed root file writes on Apple's Private Cloud Compute and redirection of node telemetry.
- Published
- Collected
Skip to content