CVE-2026-66061 Details
Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.
A vulnerability in the Home Assistant iOS Companion app, prior to version 2026.5.0, allows untrusted applications to send NFC or QR tag links to Home Assistant without user validation. The app treats these links as if they were physically scanned, automatically executing the associated automations on the user's Home Assistant server. This issue arises from the app's handling of iOS universal links, which can be invoked by any other app on the device. The vulnerability enables unauthorized automation execution, such as unlocking doors or disarming alarms, without the user's knowledge or consent.
Users can update the Home Assistant iOS Companion app to version 2026.5.0 or later, which includes a fix that requires explicit user approval before any tag is sent to Home Assistant. For those unable to upgrade immediately, it is advised to avoid linking sensitive automations to tag scans or to use additional conditions to gate those automations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/home-assistant/core/security/advisories/GHSA-j23v-9672-677j | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/home-assistant/core/security/advisories/GHSA-j23v-9672-677j | [email protected] | AdvisoryRemedyVendor |
| https://github.com/home-assistant/iOS/commit/45e05e6666c74fdbea44cc4d6fb103043fff6fd9 | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Home Assistant Companion | < 2026.5.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion