๐Ÿ” CVE Alert

CVE-2026-44698

HIGH 8.3

Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation of the JavaScript callback identifier allows a cross-origin iframe rendered inside the Companion app to execute arbitrary JavaScript in the Home Assistant frontend's main-frame origin and exfiltrate the signed-in user's access token. This vulnerability is fixed in 2026.4.1 for iOS and 2026.4.4 for Android.

CWE CWE-94 CWE-346 CWE-749 CWE-940
Vendor home-assistant
Product core
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for home-assistant core

Be the first to know when new high vulnerabilities affecting home-assistant core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

home-assistant / core
< 2026.4.4
Home Assistant / Companion app (iOS)
< 2026.4.1
Home Assistant / Companion app (Android)
< 2026.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/home-assistant/core/security/advisories/GHSA-7jp2-p2fw-mgvf