CVE-2026-84600Medium· 5.4▾ TwilightPoC availableAn authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user conf…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
1 GitHub repo
— → 5.4
none → medium
Last analysed / modified upstream
0.2% → 0.2%
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
ipados < 27.0iphone_os < 27.0macos < 27.0tvos < 27.0visionos < 27.0watchos < 27.0Upgrade past the affected range:
ipados 27.0iphone_os 27.0macos 27.0tvos 27.0visionos 27.0watchos 27.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-43695Medium· 5.5An authorization issue was addressed with improved state management
CVE-2026-84615Medium· 5.5An authorization issue was addressed with improved state management
CVE-2026-84636Medium· 5.5An authorization issue was addressed with improved state management
CVE-2026-65349Medium· 6.6An out-of-bounds read was addressed with improved input validation
CVE-2026-65343High· 7.5A use after free issue was addressed with improved memory management
CVE-2026-84616Medium· 5.5A type confusion issue was addressed with improved memory handling