# igloohome Smart Lock App Exposes Backend Secrets

Published: 2026-07-28 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/44b22f9c-800f-58ca-b87d-af69ecb18b6d/igloohome-smart-lock-app-exposes-backend-secrets

> A hardcoded-secrets flaw in igloohome's Android smart lock app could let attackers reach unauthenticated backend functions.

CISA published an ICS advisory disclosing CVE-2026-16581, an Inclusion of Sensitive Information in Source Code vulnerability (CWE-540) affecting igloohome's Smart Lock Mobile Application for Android, version 3.2.3 and prior. The flaw stems from sensitive information embedded in the app's source code that could allow an unauthorized actor to access backend functions or services not sufficiently protected by authentication controls.

igloohome, a Singapore-headquartered smart lock vendor with worldwide deployment in the commercial facilities sector, has released a vendor fix enhancing access control mechanisms on backend services so only properly authenticated and authorized requests can interact with sensitive functionality. No user action is required to apply the remediation. The vulnerability was reported to CISA by researcher Vincent C. of CodeVispera, and CISA states no known public exploitation has been observed at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2026-16581

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/44b22f9c-800f-58ca-b87d-af69ecb18b6d/igloohome-smart-lock-app-exposes-backend-secrets.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
