MEDIUM
CVE-2026-84600
CVSS
5.4
Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
Weakness (CWE)
CWE-285
Improper Authorization
EPSS Score
0.22%
Probability of exploitation in next 30 days
12.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.