logo

CISA in a flap as Chirp smart door locks can be trivially unlocked remotely

ID: dc1e1ea4-999d-5305-bf77-f48050007582

STIX ID: report--dc1e1ea4-999d-5305-bf77-f48050007582

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-04-15

Date Updated: 2026-04-26

Author: Matthew Connatser

...
...

### Executive Summary Chirp Systems' Android app contained hard-coded credentials and private keys that allowed attackers to impersonate the developer via an August API, enumerate and remotely unlock Chirp-powered smart locks (CVE-2024-2197, CVSS 9.1). CISA issued an advisory and the issue was disclosed by a security researcher who found the credentials in a decompiled APK; Chirp updated the app after the advisory, and the report states there are no known active exploitations to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.