CVE-2026-54318: CWE-926: Improper Export of Android Application Components in home-assistant core
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it; the receiver trusts the extra and forwards it to the user's Home Assistant server as the device's real location. This bypasses Android's developer-mode "Mock Location" gate and allows a local malicious app to drive zone-based automations (unlock door / disarm alarm / open garage) by faking the user's GPS position. This vulnerability is fixed in 2026.5.3.
AI Analysis
Technical Summary
CVE-2026-54318 is an improper export vulnerability (CWE-926) in Home Assistant core's LocationSensorManager BroadcastReceiver prior to version 2026.5.3. The receiver is exported with no permission checks, allowing any local app to broadcast a forged Google Play Services LocationResult. The receiver trusts this data and forwards it as the device's real location to the Home Assistant server. This bypasses Android's developer-mode mock location restrictions and enables local malicious apps to manipulate location-based automations such as unlocking doors or disarming alarms. The vulnerability is resolved in version 2026.5.3.
Potential Impact
An attacker with a local app installed on the device, requiring no special permissions, can spoof the device's GPS location as perceived by Home Assistant. This can lead to unauthorized triggering of zone-based automations, potentially compromising physical security controls like door locks, alarms, and garage doors. There is no impact on confidentiality or availability, but the integrity of location data and automation triggers is compromised.
Mitigation Recommendations
Upgrade Home Assistant core to version 2026.5.3 or later, where this vulnerability is fixed. No other mitigation is indicated or required as the fix addresses the improper export of the BroadcastReceiver.
CVE-2026-54318: CWE-926: Improper Export of Android Application Components in home-assistant core
Description
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it; the receiver trusts the extra and forwards it to the user's Home Assistant server as the device's real location. This bypasses Android's developer-mode "Mock Location" gate and allows a local malicious app to drive zone-based automations (unlock door / disarm alarm / open garage) by faking the user's GPS position. This vulnerability is fixed in 2026.5.3.
CVSS v3.1
Score 7.1high
Affected software
pkg:github/home-assistant/coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54318 is an improper export vulnerability (CWE-926) in Home Assistant core's LocationSensorManager BroadcastReceiver prior to version 2026.5.3. The receiver is exported with no permission checks, allowing any local app to broadcast a forged Google Play Services LocationResult. The receiver trusts this data and forwards it as the device's real location to the Home Assistant server. This bypasses Android's developer-mode mock location restrictions and enables local malicious apps to manipulate location-based automations such as unlocking doors or disarming alarms. The vulnerability is resolved in version 2026.5.3.
Potential Impact
An attacker with a local app installed on the device, requiring no special permissions, can spoof the device's GPS location as perceived by Home Assistant. This can lead to unauthorized triggering of zone-based automations, potentially compromising physical security controls like door locks, alarms, and garage doors. There is no impact on confidentiality or availability, but the integrity of location data and automation triggers is compromised.
Mitigation Recommendations
Upgrade Home Assistant core to version 2026.5.3 or later, where this vulnerability is fixed. No other mitigation is indicated or required as the fix addresses the improper export of the BroadcastReceiver.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-12T18:42:02.223Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a3acbe4eed863c81e6c9a61
Added to database: 06/23/2026, 18:09:40 UTC
Last enriched: 06/30/2026, 23:20:42 UTC
Last updated: 08/04/2026, 12:46:13 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.