CISA in a flap as Chirp smart door locks can be trivially unlocked remotely
ID: dc1e1ea4-999d-5305-bf77-f48050007582
STIX ID: report--dc1e1ea4-999d-5305-bf77-f48050007582
Feed Name: The Register (Security)
### Executive Summary Chirp Systems' Android app contained hard-coded credentials and private keys that allowed attackers to impersonate the developer via an August API, enumerate and remotely unlock Chirp-powered smart locks (CVE-2024-2197, CVSS 9.1). CISA issued an advisory and the issue was disclosed by a security researcher who found the credentials in a decompiled APK; Chirp updated the app after the advisory, and the report states there are no known active exploitations to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
