Medium severity6.5NVD Advisory· Published May 18, 2026· Updated Jun 30, 2026
CVE-2026-20685
CVE-2026-20685
Description
An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.
Affected products
2cpe:2.3:a:apple:private_cloud_compute:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:private_cloud_compute:*:*:*:*:*:*:*:*range: <5e290.3
- (no CPE)range: <5E290.3
Patches
Vulnerability mechanics
References
1News mentions
2- ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More StoriesThe Hacker News · Aug 13, 2026
- Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry LeakageCyber Security News · Aug 10, 2026