Location Manipulation Vulnerability in Home Assistant Software by Home Assistant
CVE-2026-54318
What is CVE-2026-54318?
CVE-2026-54318 is a vulnerability found in the Home Assistant software, which is an open-source platform dedicated to home automation. The primary purpose of Home Assistant is to allow users to control smart devices in their homes locally, maintaining user privacy and control over their data. The vulnerability resides in the LocationSensorManager BroadcastReceiver, which prior to version 2026.5.3, was exported without appropriate permission settings. This configuration flaw enables any installed application, even those without runtime permissions, to send a falsified location report to the Home Assistant server. The exploitation of this vulnerability allows a malicious app to bypass Android’s mock location restrictions, manipulating the user's GPS data. Consequently, an attacker may automate or trigger actions that rely on location data, such as unlocking doors or disarming security systems, without the user’s consent or knowledge.
Potential impact of CVE-2026-54318
-
Unauthorized Access to Home Systems: The ability for attackers to spoof a user's location could lead to unauthorized access to smart home systems, compromising security features designed to protect the home environment.
-
Execution of Automated Actions: Malicious actors could enact automated controls, such as unlocking doors or disabling alarms based on forged location data, potentially facilitating burglaries or other malicious activities.
-
Breach of Privacy and Control: This vulnerability undermines the fundamental promise of privacy and local control offered by Home Assistant, exposing users to risks of surveillance or unwanted intrusion by rogue applications.
Affected Version(s)
core < 2026.5.3
