PT-2026-51577 · Home Assistant · Core
Waihankan
·
Published
2026-06-23
·
Updated
2026-06-23
·
CVE-2026-54318
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions prior to 2026.5.3
Description
The LocationSensorManager BroadcastReceiver is exported without requiring permissions. This allows any installed application on the device, regardless of its runtime permissions, to send a forged Google Play Services LocationResult to the receiver. The receiver trusts this data and forwards it to the Home Assistant server as the actual device location. This process bypasses the Android developer-mode Mock Location gate, enabling a malicious local application to trigger zone-based automations, such as unlocking doors, disarming alarms, or opening garages, by spoofing the GPS position.
Recommendations
Update to version 2026.5.3.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Core