PT-2026-28467 · Google+1 · Android Auto+1
Pwnpanda
·
Published
2026-03-27
·
Updated
2026-03-29
·
CVE-2026-33045
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions 2025.02 through 2026.01
Description
The "remaining charge time" sensor for mobile phones (imported from Android Auto) in Home Assistant is susceptible to cross-site scripting (XSS). This issue is similar to CVE-2025-62172. The History-graph card displays the name of the entity without proper output escaping or sanitization, allowing for the injection of arbitrary tags, including JavaScript. A malicious actor can exploit this by changing the name of the sensor to include a malicious payload, which is then executed when a user hovers over the graph. The impact of this vulnerability could allow an attacker to perform account takeover. The vulnerability appears to rely on the use of Android Auto, but may also be triggered by other devices with the same sensor.
Recommendations
Update to version 2026.01 or later to resolve this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Auto
Home Assistant