
[1day1line] CVE-2026-54318: Unauthorized Trigger for GPS Location Spoofing-based Automation Due to Improper Component Export in Home Assistant Hello, this is newp1ayer48. Today's 1day1line is about an unauthorized trigger vulnerability in the Open Home Foundation's Home Assistant, which involves GPS location spoofing-based automation caused by an improper component export. This vulnerability occurs when a pre-component is exposed externally. Please refer to the blog post for more details! https://hackyboiz.github.io/2026/07/11/newp1ayer48/CVE-2026-54318/
Post summary
A new CVE for Home Assistant has been disclosed, exposing GPS spoofing via an improperly exported component. No evidence of PoC, exploit availability, active attacks, or available fixes is provided.

