Local Control Vulnerability in Home Assistant iOS Companion App
CVE-2026-66061

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-66061?

The Home Assistant iOS Companion app allows execution of automations based on NFC or QR tag links without sufficient validation. Prior to version 2026.5.0, it treated tag links from untrusted apps as if they were from legitimate sources, enabling unauthorized execution of automations. This poses a risk of silent automation triggered by malicious local applications, potentially leading to unattended operations that could compromise user control and privacy.

Affected Version(s)

core < 2026.5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.