5.4
CVE-2026-84600
- EPSS 0.16%
- Veröffentlicht 14.09.2026 20:49:55
- Zuletzt bearbeitet 18.09.2026 13:50:58
- Erkennungen
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.059 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://support.apple.com/en-us/149034
https://support.apple.com/en-us/149035
https://support.apple.com/en-us/149038
https://support.apple.com/en-us/149036
https://support.apple.com/en-us/149037