Client-Side Request Forgery in Home Assistant iOS/macOS native Apps
CVE-2023-44385

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
19 October 2023

What is CVE-2023-44385?

The Home Assistant Companion application for iOS and macOS versions up to 2023.4 is susceptible to Client-Side Request Forgery (CSRF). Attackers can exploit this vulnerability by sending users malicious links or QR codes. Upon interaction, these links can lead the user to trigger arbitrary services within their Home Assistant setup. This situation poses a significant risk, potentially leading to unauthorized access and remote code execution. Users are strongly recommended to upgrade to version 2023.7 or later as there are no viable workarounds for this issue.

Affected Version(s)

core < 2023.7

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.