Location Manipulation Vulnerability in Home Assistant Software by Home Assistant
CVE-2026-54318

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54318?

CVE-2026-54318 is a vulnerability found in the Home Assistant software, which is an open-source platform dedicated to home automation. The primary purpose of Home Assistant is to allow users to control smart devices in their homes locally, maintaining user privacy and control over their data. The vulnerability resides in the LocationSensorManager BroadcastReceiver, which prior to version 2026.5.3, was exported without appropriate permission settings. This configuration flaw enables any installed application, even those without runtime permissions, to send a falsified location report to the Home Assistant server. The exploitation of this vulnerability allows a malicious app to bypass Android’s mock location restrictions, manipulating the user's GPS data. Consequently, an attacker may automate or trigger actions that rely on location data, such as unlocking doors or disarming security systems, without the user’s consent or knowledge.

Potential impact of CVE-2026-54318

  1. Unauthorized Access to Home Systems: The ability for attackers to spoof a user's location could lead to unauthorized access to smart home systems, compromising security features designed to protect the home environment.

  2. Execution of Automated Actions: Malicious actors could enact automated controls, such as unlocking doors or disabling alarms based on forged location data, potentially facilitating burglaries or other malicious activities.

  3. Breach of Privacy and Control: This vulnerability undermines the fundamental promise of privacy and local control offered by Home Assistant, exposing users to risks of surveillance or unwanted intrusion by rogue applications.

Affected Version(s)

core < 2026.5.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.