Home Assistant Companion Apps Vulnerability Enables Token Theft (heise.de)
0xBASE INTEL BRIEF
- CVE-2026-44698, CVSS 8.3, high severity vulnerability
- Token theft via cross-origin iframe and WebView bridge injection
- Patches: Android 2026.4.4, iOS 2026.4.1
"A vulnerability (CVE-2026-44698, CVSS 8.3) in the Home Assistant Companion apps for Android and iOS allows attackers to steal access tokens through a malicious WebView iframe, leading to full instance takeover. Patches are available: Android 2026.4.4, iOS 2026.4.1. Users are advised to remove third-party webpage cards from dashboards as a workaround."
#security vulnerability
#IoT security
#access token theft
no comments yet.