An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sandboxed process may be able to circumvent sandbox restrictions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HApple Shortcuts
APPApple< 2.1.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-7289MEDIUM5.5same product
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is ...
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same vendor
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same vendor
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same vendor
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same vendor
Apple — memory corruption (RCE) w przetwarzaniu strumieni audio