Location Manipulation Vulnerability in Home Assistant Software by Home Assistant
CVE-2026-54318
7.1HIGH
What is CVE-2026-54318?
The Home Assistant software experiences a vulnerability in its LocationSensorManager BroadcastReceiver, which is improperly configured to be exported without permissions. This flaw allows any installed application to broadcast misleading location data, effectively bypassing Android's built-in security measures against location spoofing. As a result, malicious applications can simulate the user's GPS position, potentially triggering automated responses such as unlocking doors or disarming alarms. This flaw has been resolved in version 2026.5.3, emphasizing the importance of keeping software updated to mitigate such risks.
Affected Version(s)
core < 2026.5.3
