Machine-generated analysis · WAYSCloud LLM
Version 3.2.3 and earlier of the igloohome Smart Lock Mobile Application for Android contain source code that includes sensitive information, potentially allowing unauthorized access to backend services.
Context
The affected product is the igloohome Smart Lock Mobile Application for Android, version 3.2.3 and prior. The advisory states that inclusion of sensitive information in the source code could let an unauthorized actor access functions or backend services that lack sufficient authentication controls. igloohome has released a fix that enhances access-control mechanisms on those backend services, and no user interaction is required to apply it.
Operator considerations
Check: Verify that deployed devices are running version 3.2.3 or earlier.
Patch: Apply igloohome’s updated application that strengthens backend access controls.
Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.
The following versions of igloohome Smart Lock Mobile Application are affected:
Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581)
Vendor
Equipment
igloohome
igloohome Smart Lock Mobile Application
Inclusion of Sensitive Information in Source Code
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Singapore
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
igloohome Smart Lock Mobile Application
MitigationFor more information, contact igloohome (info@igloohom...
Read the full advisory on CISA →