CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Johnson Controls XAAP Android

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3118

As cited

Copy frozen at (site build).

vulnerabilities

Johnson Controls XAAP Android

Johnson Controls XAAP Android versions prior to 1.53 contain a cleartext storage vulnerability (CVE-2026-34490) that allows attackers with physical device access or those who exploit a separate flaw to read sensitive application data in plaintext. The vulnerability has a CVSS score of 3.3 (low severity) and requires local access without network involvement. Johnson Controls recommends updating to version 1.53 or later and implementing device hardening measures including encryption, screen locks, and mobile device management policies.

Why it matters: Critical infrastructure operators deploying Johnson Controls XAAP Android should update immediately and restrict physical access to devices to prevent potential exposure of sensitive information stored on Android devices.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Johnson Controls XAAP Android

Johnson Controls XAAP Android versions prior to 1.53 contain a cleartext storage vulnerability (CVE-2026-34490) that allows attackers with physical device access or those who exploit a separate flaw to read sensitive application data in plaintext. The vulnerability has a CVSS score of 3.3 (low severity) and requires local access without network involvement. Johnson Controls recommends updating to version 1.53 or later and implementing device hardening measures including encryption, screen locks, and mobile device management policies.

Why it matters: Critical infrastructure operators deploying Johnson Controls XAAP Android should update immediately and restrict physical access to devices to prevent potential exposure of sensitive information stored on Android devices.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary