This is actually a somewhat complicated technical issue.
Apple designed a whole fancy cryptographic system for this but then ultimately opted not to deploy it.
I'm having some trouble finding their writeup, but here's my summary:
educatedguesswork.org/posts/apple-...
educatedguesswork.org
Overview of Apple's Client-side CSAM Scanning