logo

US government says security flaw in Chirp Systems’ app lets anyone remotely control smart home locks

ID: f324e479-c0d5-5b9f-942b-4a2812b95c43

STIX ID: report--f324e479-c0d5-5b9f-942b-4a2812b95c43

Feed Name: TechCrunch Security News

Threat Score
30/100

Date Published: 2024-04-22

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

CISA published an advisory about Chirp Systems' mobile apps hardcoding a credential ("BEACON_PASSWORD") that could be extracted and, within Bluetooth range, used to prevent the app from notifying users when near a compatible smart lock; the vendor had not responded to prior disclosure requests and the issue went unpatched for years, but CISA later downgraded the advisory saying the vulnerability could not enable remote takeover of locks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.