top of page
perceptive_background_267k.jpg

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home As…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 15:02:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies

Home Assistant Companion apps for Android and iOS contain a vulnerability that exposes JavaScript bridges to all frames, including cross-origin iframes. The flaw allows arbitrary JavaScript execution in the main-frame origin and potential exfiltration of user access tokens. The vulnerability affects versions prior to 2026.4.1 for iOS and 2026.4.4 for Android. Attackers can exploit unsanitized interpolation of JavaScript callback identifiers through cross-origin iframes rendered within the Companion app. This represents a significant security risk for home automation systems using Home Assistant.

Technical details

Mitigation steps:

Affected products:

Home Assistant Companion

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page