What is CVE-2026-66061?
In Home Assistant, the iOS Companion app mishandles tag links (NFC or QR) delivered via universal links, treating them as physically scanned without proper validation. This could allow remote triggering of automations. Users should update to version 2026.5.0.
Azərbaycanca: Home Assistant platformasında iOS Companion tətbiqi, universal linklər vasitəsilə ötürülən NFC və ya QR etiket bağlantılarını fiziki skan kimi qəbul edərək düzgün yoxlamır. Bu, zərərli istifadəçilərə uzaqdan avtomatlaşdırma triggerlərini işə salmağa imkan yaradır. 2026.5.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
How does CVE-2026-66061 affect automations in the Home Assistant iOS Companion app?
Due to the vulnerability, NFC or QR tag links delivered via universal links are treated as physically scanned, which could allow remote triggering of automations.
Which version should be updated to in order to fix CVE-2026-66061?
Users are recommended to update Home Assistant to version 2026.5.0 to address this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.