Johnson Controls XAAP Android Stores Data Unencrypted
A cleartext storage flaw in Johnson Controls' XAAP Android app could let attackers with physical device access read sensitive data in plaintext.
CISA published an advisory for a vulnerability in Johnson Controls' XAAP Android application (Fire Solutions), tracked as CVE-2026-34490. The app stores application data locally on the device without encryption, meaning an attacker who already has physical access to the device—or who has compromised it through a separate, unrelated flaw—could read the stored data in plaintext. The issue is classified under CWE-312 (Cleartext Storage of Sensitive Information) and requires no network access, limiting exploitation to the local device environment.
The vulnerability affects all versions of XAAP Android prior to 1.53, deployed worldwide across the Critical Manufacturing sector. Johnson Controls has released version 1.53 to remediate the flaw and recommends additional mitigations including restricting physical device access, enforcing Android OS hardening and device encryption, deploying MDM solutions, and avoiding rooting or jailbreaking of production devices. No public exploitation of this vulnerability has been reported to CISA at this time, and the flaw cannot be exploited remotely, limiting its overall real-world urgency.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free