As cited
Copy frozen at (site build).
vulnerabilities
Johnson Controls XAAP Android
Johnson Controls XAAP Android versions prior to 1.53 contain a cleartext storage vulnerability (CVE-2026-34490) that allows attackers with physical device access or those who exploit a separate flaw to read sensitive application data in plaintext. The vulnerability has a CVSS score of 3.3 (low severity) and requires local access without network involvement. Johnson Controls recommends updating to version 1.53 or later and implementing device hardening measures including encryption, screen locks, and mobile device management policies.
Why it matters: Critical infrastructure operators deploying Johnson Controls XAAP Android should update immediately and restrict physical access to devices to prevent potential exposure of sensitive information stored on Android devices.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Johnson Controls XAAP Android
Johnson Controls XAAP Android versions prior to 1.53 contain a cleartext storage vulnerability (CVE-2026-34490) that allows attackers with physical device access or those who exploit a separate flaw to read sensitive application data in plaintext. The vulnerability has a CVSS score of 3.3 (low severity) and requires local access without network involvement. Johnson Controls recommends updating to version 1.53 or later and implementing device hardening measures including encryption, screen locks, and mobile device management policies.
Why it matters: Critical infrastructure operators deploying Johnson Controls XAAP Android should update immediately and restrict physical access to devices to prevent potential exposure of sensitive information stored on Android devices.
- Source published
- First seen by Cybersecurity Tracker