Junglewise Threat Intelligence

CVE-2026-84600: Apple iOS and iPadOS authorization bypass via Shortcuts

CVE-2026-84600 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple macOS Golden Gate, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's Shortcuts app—a feature that allows users to create automated tasks—contained an authorization flaw that could allow a malicious shortcut to send messages without the user's permission. This could enable phishing attacks, message-based scams, or unauthorized communications sent from a victim's device. The vulnerability was patched in iOS 27 and iPadOS 27 released on September 14, 2026.

Technical details

An authorization state management issue in Apple's Shortcuts framework allowed malicious shortcuts to bypass user confirmation prompts required for sending messages. The vulnerability stems from improper handling of permission state transitions in the shortcut execution engine. An attacker would need to distribute a malicious shortcut that the user installs and executes—either through social engineering or a compromised shortcut repository. Upon execution, the shortcut could send SMS, iMessage, or other messages without triggering the standard user confirmation dialog, leading to unauthorized message transmission. Apple patched this in iOS 27 and related OS releases by improving state management during shortcut authorization checks.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84600 disclosed and patched in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27

References

Related threats