Impact
The Home Assistant iOS Companion app treats NFC and QR tag links received by iOS universal links as if they were physically scanned, without validating the originating app or asking for user confirmation. This flaw allows an attacker to create a malicious app that forwards a tag link directly to Home Assistant, causing the system to run the linked automation as though a legitimate user had scanned the tag. The result is silent, unattended automation execution, which can lead to unauthorized actions being performed on the home network.
Affected Systems
This vulnerability affects Home Assistant "core" versions released before 2026.5.0. All installations of the iOS Companion app associated with those releases are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not known to be actively exploited yet. The likely attack vector is a local iOS device; an untrusted application installed on the device can forward the NFC/QR tag via universal links without the user’s knowledge. Because no network or privileged access is required, the condition for exploitation is relatively simple on a compromised device.
OpenCVE Enrichment