Executive brief
A security vulnerability in the Tuya Smart Life mobile application allows unauthorized individuals to gain control over smart home devices that use the Matter protocol. This app is used to manage various smart home appliances, and an exploit could allow an attacker to manipulate household devices without permission. This poses a significant risk to user privacy and the physical security of the smart home environment.
Technical details
A vulnerability classified as 'Execution with Unnecessary Privileges' (CWE-250) exists in the Tuya Smart Life App version 5.6.1. The flaw resides in the implementation of the Matter protocol fabric, which fails to properly restrict control permissions. A remote attacker can exploit this to gain unauthorized control over Matter-enabled IoT devices managed by the app without requiring prior authentication or elevated privileges. The attack vector is network-based and does not require user interaction. While the advisory confirms the vulnerability in version 5.6.1, users should check for updated versions of the app to mitigate the risk.
Affected products
- Tuya Smart Life App 5.6.1
Timeline
- 2025-09-16: disclosed
- 2025-09-16: advisory