An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
References
Configurations
No configuration.
History
17 Sep 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-285 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
Information
Published : 2026-09-14 21:17
Updated : 2026-09-17 15:16
NVD link : CVE-2026-84600
Mitre link : CVE-2026-84600
CVE.ORG link : CVE-2026-84600
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
