[CVE-2026-20685] Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
blog.sentry.security | 研究 | CVE-2026-20685 | #ai-security | #bug-bounty | #cloud | #path-traversal | #apple | #private-cloud-compute | #cve-2026-20685
摘要
Sentry 研究员因 CVE-2026-20685 获 15 万美元赏金:Apple Private Cloud Compute 节点配置组件 darwin-init 存在路径穿越漏洞,可以 root 权限写入文件并将节点遥测重定向,危及 PCC 隐私保证。
- 发布时间
- 收录时间
Skip to content