The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.
CVE ID: CVE-2024-27855
Vendor: Apple
Product: iOS and iPadOS
EPSS Score: 0.12% (probability of being exploited)
EPSS Percentile: 47.87% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)