Executive brief
Apple Private Cloud Compute (PCC) is a cloud-based system designed to handle complex AI processing while maintaining user privacy. A security flaw in how the system handles file paths could allow an attacker with access to the local network to intercept or leak sensitive information. This could potentially compromise the privacy guarantees of the cloud environment, though Apple has released a fix in PCC Release 5E290.3.
Technical details
A path handling vulnerability exists in Apple's Private Cloud Compute (PCC) environment. The flaw stems from insufficient validation of file or resource paths, which could be exploited by an attacker in a privileged network position (such as an adjacent network or man-in-the-middle scenario) to leak sensitive data. Apple addressed the issue by improving path validation logic. The vulnerability is resolved in PCC Release 5E290.3.
Affected products
- Apple Private Cloud Compute (PCC) Before 5E290.3
Timeline
- 2026-05-18: disclosed
- 2026-05-18: patched: Fixed in PCC Release 5E290.3