igloohome Smart Lock Mobile Application
Summary
A vulnerability, CVE-2026-16581, has been identified in igloohome Smart Lock Mobile Application versions 3.2.3 and prior. This "Inclusion of Sensitive Information in Source Code" flaw could allow unauthorized actors to access sensitive functions or backend services. igloohome has addressed this by enhancing access control mechanisms on their backend services.
IFF Assessment
The vulnerability allows unauthorized access to sensitive functions and backend services, posing a risk to users' smart lock data and control.
Severity
The CVSS score of 5.3 reflects a moderate severity, indicating that the vulnerability is exploitable and can lead to unauthorized access to functions or backend services, potentially compromising sensitive information.
Defender Context
This alert highlights the importance of securing mobile applications, especially those controlling physical access like smart locks. Defenders should be aware of vulnerabilities related to sensitive information exposure in source code and ensure thorough security testing of IoT device applications. Patches should be applied promptly to mitigate risks of unauthorized access and data compromise.