VORANT. Threat Intelligence Sign in Get the full feed

igloohome Smart Lock App Exposes Backend Secrets

low vulnerability technology

A hardcoded-secrets flaw in igloohome's Android smart lock app could let attackers reach unauthenticated backend functions.

CISA published an ICS advisory disclosing CVE-2026-16581, an Inclusion of Sensitive Information in Source Code vulnerability (CWE-540) affecting igloohome's Smart Lock Mobile Application for Android, version 3.2.3 and prior. The flaw stems from sensitive information embedded in the app's source code that could allow an unauthorized actor to access backend functions or services not sufficiently protected by authentication controls.

igloohome, a Singapore-headquartered smart lock vendor with worldwide deployment in the commercial facilities sector, has released a vendor fix enhancing access control mechanisms on backend services so only properly authenticated and authorized requests can interact with sensitive functionality. No user action is required to apply the remediation. The vulnerability was reported to CISA by researcher Vincent C. of CodeVispera, and CISA states no known public exploitation has been observed at this time.

Mentioned in this report

Vulnerabilities CVE-2026-16581

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free