


Perceptive Security
SOC/SIEM Consultancy

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home As…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 15:02:48
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies
Home Assistant Companion apps for Android and iOS contain a vulnerability that exposes JavaScript bridges to all frames, including cross-origin iframes. The flaw allows arbitrary JavaScript execution in the main-frame origin and potential exfiltration of user access tokens. The vulnerability affects versions prior to 2026.4.1 for iOS and 2026.4.4 for Android. Attackers can exploit unsanitized interpolation of JavaScript callback identifiers through cross-origin iframes rendered within the Companion app. This represents a significant security risk for home automation systems using Home Assistant.
Technical details
Mitigation steps:
Affected products:
Home Assistant Companion
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44698
https://github.com/home-assistant/core/security/advisories/GHSA-7jp2-p2fw-mgvf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
