Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Home-assistant
Home-assistant companion App Home-assistant core |
|
| Vendors & Products |
Home-assistant
Home-assistant companion App Home-assistant core |
Fri, 29 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation of the JavaScript callback identifier allows a cross-origin iframe rendered inside the Companion app to execute arbitrary JavaScript in the Home Assistant frontend's main-frame origin and exfiltrate the signed-in user's access token. This vulnerability is fixed in 2026.4.1 for iOS and 2026.4.4 for Android. | |
| Title | Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection | |
| Weaknesses | CWE-346 CWE-749 CWE-94 CWE-940 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T13:58:53.347Z
Reserved: 2026-05-07T17:07:09.316Z
Link: CVE-2026-44698
Updated: 2026-05-29T13:58:49.847Z
Status : Awaiting Analysis
Published: 2026-05-29T14:16:28.823
Modified: 2026-05-29T16:25:57.843
Link: CVE-2026-44698
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:46:28Z