Junglewise Threat Intelligence

CVE-2026-16581: igloohome Smart Lock Mobile App sensitive information disclosure

CVE-2026-16581 · Severity: medium · CVSS 5.3 · Published 2026-07-28

Executive brief

The igloohome Smart Lock mobile application, used to manage and operate smart locks, contains sensitive information within its publicly accessible source code. An unauthorized individual could use this information to bypass security controls and access backend services or functions that should be restricted. This could potentially lead to unauthorized access to lock management systems or customer data.

Technical details

A vulnerability (CWE-540) exists in the igloohome Smart Lock Mobile App (Android) versions 3.2.3 and prior due to the inclusion of sensitive information in the application's source code. This information can be leveraged by an unauthenticated attacker over the network to interact with backend services that lack sufficient authentication controls. Successful exploitation allows access to restricted functions or data. The vendor has addressed the issue by enhancing access control mechanisms on their backend services to ensure all requests are properly authenticated and authorized.

Affected products

  • igloohome Smart Lock Mobile Application (Android) 3.2.3 and prior

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References