Impact
The vulnerability is an authorization flaw in Apple’s shortcut framework that allows a malicious shortcut to trigger the message‑sending API without a user prompt, bypassing the normal confirmation step and enabling silent message or contact transmission. The weakness is classified as CWE-285.
Affected Systems
Apple operating systems that include the shortcut framework are affected: iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Versions prior to those releases that lack the state‑management fix are presumed vulnerable until updated.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is reported as < 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local; a malicious shortcut executed on the device—such as via a bundled application or a downloaded shortcut—can send messages without user approval.
OpenCVE Enrichment