
Information on the security content of Apple software updates
Impact: A malicious shortcut may be able to send messages without user confirmation.
Description: An authorization issue was addressed with improved state management.
Products: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Fixed In:
Research Context: Reported against pre-release software.
Credit: Owen Pawling (@owenpawling)
CWE-285: Improper Authorization
Source: CISA ADP
Base Score: 5.4 (MEDIUM)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
| Metric | Value |
|---|---|
| Attack Vector (AV) | Network |
| Attack Complexity (AC) | Low |
| Privileges Required (PR) | None |
| User Interaction (UI) | Required |
| Scope (S) | Unchanged |
| Confidentiality (C) | Low |
| Integrity (I) | Low |
| Availability (A) | None |
| Decision Point | Value |
|---|---|
| Exploitation | None |
| Automatable | No |
| Technical Impact | Partial |
CVE ID: CVE-2026-84600
Reported to Apple: June 14, 2026
CNA: Apple
Status: Published
Reserved: September 1, 2026
Published: September 14, 2026
Last Updated: September 17, 2026