← Back to Feed
igloohome Smart Lock Mobile Application
CVE-2026-16581
July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL
This advisory details a vulnerability in igloohome Smart Lock Mobile Application version 3.2.3 for Android, where sensitive information is included in source code. This could let an unauthorized actor access backend services not protected by authentication. igloohome has released a fix that requires no user interaction.
Key Takeaways
- igloohome Smart Lock Mobile App version 3.2.3 exposes sensitive information in source code.
- This vulnerability allows unauthorized access to functions or backend services.
- The vendor fixed the issue by enhancing access control on backend services.