CVE-2026-84600
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.4epss 0.3%
from disclosure to weapon2 days
Published on NVDSep 14
1st PoC+2d
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
public PoCs found — 1
githubgithub.com/OwenPawl/CVE-2026-84600★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.