Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Message Transmission
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authorization flaw in Apple’s shortcut framework that allows a malicious shortcut to trigger the message‑sending API without a user prompt, bypassing the normal confirmation step and enabling silent message or contact transmission. The weakness is classified as CWE-285.

Affected Systems

Apple operating systems that include the shortcut framework are affected: iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Versions prior to those releases that lack the state‑management fix are presumed vulnerable until updated.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is reported as < 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local; a malicious shortcut executed on the device—such as via a bundled application or a downloaded shortcut—can send messages without user approval.

Generated by OpenCVE AI on September 20, 2026 at 20:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OS updates that include iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.
  • Remove or disable any shortcuts that are configured to send messages without user confirmation, or revoke the shortcut permission that allows message transmission.
  • Educate users to review shortcut details and exercise caution before executing shortcuts that perform automatic actions.

Generated by OpenCVE AI on September 20, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Shortcut Framework Authorization Bypass Allowing Silent Message Transmission

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Shortcut Authorization Bypass Enabling Unsolicited Messaging
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Shortcut Authorization Bypass Enabling Unsolicited Messaging
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:33:52.562Z

Reserved: 2026-09-01T21:13:17.759Z

Link: CVE-2026-84600

cve-icon Vulnrichment

Updated: 2026-09-17T14:33:42.919Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:35.507

Modified: 2026-09-18T13:50:58.320

Link: CVE-2026-84600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:00:05Z

Weaknesses