Apple OS Shortcuts Auth Bypass via StateMgmt
CVE-2026-84600 Published on September 14, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
Vulnerability Analysis
CVE-2026-84600 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-84600 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-84600
Want to know whenever a new CVE is published for Apple products? stack.watch will email you.
Affected Versions
Apple iOS and iPadOS:- Before 27 is affected.
- Before 27 is affected.
- Before 27 is affected.
- Before 27 is affected.
- Before 27 is affected.