Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.
Published: 2026-08-07
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Home Assistant iOS Companion app treats NFC and QR tag links received by iOS universal links as if they were physically scanned, without validating the originating app or asking for user confirmation. This flaw allows an attacker to create a malicious app that forwards a tag link directly to Home Assistant, causing the system to run the linked automation as though a legitimate user had scanned the tag. The result is silent, unattended automation execution, which can lead to unauthorized actions being performed on the home network.

Affected Systems

This vulnerability affects Home Assistant "core" versions released before 2026.5.0. All installations of the iOS Companion app associated with those releases are susceptible.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not known to be actively exploited yet. The likely attack vector is a local iOS device; an untrusted application installed on the device can forward the NFC/QR tag via universal links without the user’s knowledge. Because no network or privileged access is required, the condition for exploitation is relatively simple on a compromised device.

Generated by OpenCVE AI on August 7, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Home Assistant to version 2026.5.0 or newer to apply the vendor patch. This removes the insecure forwarding of NFC/QR tag links.
  • Remove or disable any untrusted third‑party iOS applications that could forward NFC or QR tag data via universal links to the Home Assistant app. If the device has multiple user accounts, ensure all accounts are free of malicious apps.
  • Configure the iOS Companion app to reject external link schemes or require explicit user confirmation before executing any tag‑associated automation, if the app offers such a setting. If not available, consider updating to the latest iOS version which may provide additional security controls over universal link handling.

Generated by OpenCVE AI on August 7, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Home-assistant
Home-assistant core
Vendors & Products Home-assistant
Home-assistant core

Fri, 07 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.
Title Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Home-assistant Core
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-07T20:43:41.785Z

Reserved: 2026-07-23T23:25:28.896Z

Link: CVE-2026-66061

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T23:00:04Z

Weaknesses