Client-Side Request Forgery in Home Assistant iOS/macOS native Apps
CVE-2023-44385
What is CVE-2023-44385?
The Home Assistant Companion application for iOS and macOS versions up to 2023.4 is susceptible to Client-Side Request Forgery (CSRF). Attackers can exploit this vulnerability by sending users malicious links or QR codes. Upon interaction, these links can lead the user to trigger arbitrary services within their Home Assistant setup. This situation poses a significant risk, potentially leading to unauthorized access and remote code execution. Users are strongly recommended to upgrade to version 2023.7 or later as there are no viable workarounds for this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
core < 2023.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
