The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.
CVE ID: CVE-2024-23204
Vendor: Apple
Product: iOS and iPadOS
EPSS Score: 0.16% (probability of being exploited)
EPSS Percentile: 54.24% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)