CVE-2026-54318General(home-assistant / home_assistant_companion)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it; the receiver trusts the extra and forwards it to the user's Home Assistant server as the device's real location. This bypasses Android's developer-mode "Mock Location" gate and allows a local malicious app to drive zone-based automations (unlock door / disarm alarm / open garage) by faking the user's GPS position. This vulnerability is fixed in 2026.5.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-926

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • home_assistant_companion

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
home_assistant_companion

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-23: 1Mentions · 2026-07-11: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-11: 106-2307-11
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-231
General1
2026-07-111
Disclosure1
Full discourse2 posts
  • hackyboiz@hackyboiz2
    Disclosure

    [1day1line] CVE-2026-54318: Unauthorized Trigger for GPS Location Spoofing-based Automation Due to Improper Component Export in Home Assistant Hello, this is newp1ayer48. Today's 1day1line is about an unauthorized trigger vulnerability in the Open Home Foundation's Home Assistant, which involves GPS location spoofing-based automation caused by an improper component export. This vulnerability occurs when a pre-component is exposed externally. Please refer to the blog post for more details! https://hackyboiz.github.io/2026/07/11/newp1ayer48/CVE-2026-54318/

    Post summary

    A new CVE for Home Assistant has been disclosed, exposing GPS spoofing via an improperly exported component. No evidence of PoC, exploit availability, active attacks, or available fixes is provided.

    0401451.6K
    546 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-54318 Unprotected LocationSensorManager BroadcastReceiver in Home Assistant Prior to 2026.5.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54318

    Post summary

    The text announces CVE-2026-54318 with a brief technical description of an unprotected BroadcastReceiver in Home Assistant, but provides no PoC, exploit code, remediation, or evidence of active exploitation.

    00000107
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphome-assistanthome_assistant_companion-android-

Explore more