{"id":"CVE-2026-84600","title":"An authorization issue was addressed with improved state management","summary":"An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user conf…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-285"],"vendor":"apple","product":"ipados","affected":["ipados < 27.0","iphone_os < 27.0","macos < 27.0","tvos < 27.0","visionos < 27.0","watchos < 27.0"],"patched":["ipados 27.0","iphone_os 27.0","macos 27.0","tvos 27.0","visionos 27.0","watchos 27.0"],"published":"2026-09-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T13:50:58.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84600","references":[{"url":"https://support.apple.com/en-us/149034","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149035","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149036","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149037","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149038","label":"product-security@apple.com"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00286,"epssPercentile":0.18756,"exploits":{"github":1,"githubRepos":["https://github.com/OwenPawl/CVE-2026-84600"],"checkedAt":"2026-09-25T08:21:17.842Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T14:33:49.034335Z"},"ingestedAt":"2026-09-14T21:15:17.509Z","slug":"CVE-2026-84600","body":"## Overview\n\nAn authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.\n\n## Affected\n\n- `ipados < 27.0`\n- `iphone_os < 27.0`\n- `macos < 27.0`\n- `tvos < 27.0`\n- `visionos < 27.0`\n- `watchos < 27.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ipados 27.0`\n- `iphone_os 27.0`\n- `macos 27.0`\n- `tvos 27.0`\n- `visionos 27.0`\n- `watchos 27.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":206131,"id":"CVE-2026-84600","ts":1789658475107,"field":"exploit_available","old":"false","new":"true"},{"seq":206130,"id":"CVE-2026-84600","ts":1789658475107,"field":"cvss","old":null,"new":"5.4"},{"seq":206129,"id":"CVE-2026-84600","ts":1789658475107,"field":"severity","old":"none","new":"medium"}]}