Root cause
Privileged startup archive handling did not adequately confine output paths; mutable configuration could undermine runtime integrity assumptions.
Demonstrated impact
Researcher demonstrated configuration changes and telemetry disclosure in Apple’s virtual environment. Apple confirms potential sensitive-information leakage from a privileged network position.
Lessons for review
- Confine archive output and authenticate provisioning inputs.
- Include security-relevant mutable configuration in integrity review.
- Use the fixed PCC release and preserve the vendor’s impact prerequisites.
Award and evidence
Individual CVE award attributed to Selmanaj. Researcher-hosted Apple offer is not vendor-hosted payment confirmation. USD follows official program context; cash settlement and award date are unverified.
Read the researcher article, publication index, full Apple-authored CNA record and official currency context; reviewed the researcher-hosted offer graphic.
- Research was demonstrated in Apple’s virtual environment; production was not tested by the researcher.
- No confirmed production prompt-content leakage is claimed here.
- Award attribution is researcher-hosted; vendor CNA evidence corroborates the vulnerability and fixed version, not payout.
- No exact report, award, fix deployment or payment date was established.
Recorded timeline
- Published
- 2026-07-31explicit · Sentry’s own article listing supplies the date.
- Public Disclosure
- 2026-05-18explicit · CVE publication timestamp; detailed researcher article appeared later.
Sources and provenance
- Beyond Prompt Injection: Hacking Apple's Private Cloud Compute Drinor Selmanaj / Sentry · reviewed 2026-10-02
- Sentry article listing Sentry · reviewed 2026-10-02
- Apple CNA record for CVE-2026-20685 Apple CNA, distributed through the CVE Program · reviewed 2026-10-02
- Researcher-hosted Apple award-offer graphic Sentry · reviewed 2026-10-02
- Apple Security Bounty US-dollar program context Apple Newsroom · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.