CVE-2026-84600

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.

Scoring

CVSS base score
0
EPSS probability
0.16%
Published
2026-09-14
Last modified
2026-09-16

Affected products

Markdown version · Browse all CVEs