What is CVE-2026-66060?
A security vulnerability was found in the Home Assistant Companion app. An attacker can use a malicious app to deliver NFC or QR tag links via the OS routing mechanism, bypassing physical scan validation and user prompts, potentially triggering unauthorized actions. This affects versions prior to 2026.5.3.
Azərbaycanca: Home Assistant Companion proqramında təhlükəsizlik zəifliyi aşkarlanıb. Təcavüzkar zərərli proqram vasitəsilə NFC/QR etiket keçidlərini fiziki skan imiş kimi emal etdirməklə icazəsiz əməliyyatlar apara bilər. Bu zəiflik 2026.5.3 versiyasından əvvəlki versiyalara təsir edir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What capabilities does the CVE-2026-66060 vulnerability in the Home Assistant Companion app provide?
CVE-2026-66060 allows an attacker to use a malicious app to deliver NFC or QR tag links that are processed as if physically scanned, bypassing user prompts and potentially triggering unauthorized actions.
Which versions of the Home Assistant Companion app are affected by CVE-2026-66060?
This security vulnerability affects all versions of the Home Assistant Companion app prior to version 2026.5.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.