← Back to Feed

igloohome Smart Lock Mobile Application

CVE-2026-16581

July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL

This advisory details a vulnerability in igloohome Smart Lock Mobile Application version 3.2.3 for Android, where sensitive information is included in source code. This could let an unauthorized actor access backend services not protected by authentication. igloohome has released a fix that requires no user interaction.

Key Takeaways

  • igloohome Smart Lock Mobile App version 3.2.3 exposes sensitive information in source code.
  • This vulnerability allows unauthorized access to functions or backend services.
  • The vendor fixed the issue by enhancing access control on backend services.
☕ Buy a Coffee