CVE-2026-55844: Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a not secure network. This vulnerability is fixed in 2025.5.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Home Assistant iOS Companion Appto a version that resolves this vulnerability.Fixed in 2025.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55844?
CVE-2026-55844 has a severity rating of high with a score of 7.5.
What does CVE-2026-55844 affect?
CVE-2026-55844 affects the Home Assistant iOS Companion App by allowing it to ignore the SSID allowlist for internal network connections.
How can I mitigate CVE-2026-55844?
To mitigate CVE-2026-55844, update the iOS Companion App to version 2025.5.0 or later where the issue has been resolved.
What data could be exposed due to CVE-2026-55844?
CVE-2026-55844 could potentially leak access tokens and sensor data due to the app's improper handling of internal network SSIDs.
Is CVE-2026-55844 applicable to all versions of the Home Assistant iOS Companion App?
CVE-2026-55844 is applicable to versions prior to 2025.5.0 of the Home Assistant iOS Companion App.