US government says security flaw in Chirp Systems’ app lets anyone remotely control smart home locks
ID: f324e479-c0d5-5b9f-942b-4a2812b95c43
STIX ID: report--f324e479-c0d5-5b9f-942b-4a2812b95c43
Feed Name: TechCrunch Security News
Threat Score
CISA published an advisory about Chirp Systems' mobile apps hardcoding a credential ("BEACON_PASSWORD") that could be extracted and, within Bluetooth range, used to prevent the app from notifying users when near a compatible smart lock; the vendor had not responded to prior disclosure requests and the issue went unpatched for years, but CISA later downgraded the advisory saying the vulnerability could not enable remote takeover of locks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
