Executive brief
The Johnson Controls XAAP application for Android contains a vulnerability where sensitive information is stored in an unencrypted, plain-text format. If a mobile device is lost, stolen, or compromised (such as being jailbroken), an unauthorized person could access this sensitive data. This could lead to the exposure of user credentials or other private operational information.
Technical details
A cleartext storage of sensitive information vulnerability (CWE-312) exists in the Johnson Controls XAAP Application on Android. The root cause is the application's failure to encrypt sensitive data before writing it to local storage. An attacker with local access to a jailbroken or otherwise compromised device can bypass standard application sandboxing to read these files. This allows for the retrieval of sensitive data that should be protected. The issue is resolved in version 1.53.
Affected products
- Johnson Controls XAAP Application before 1.53
Timeline
- 2026-07-31: advisory: Initial advisory published by Johnson Controls and NVD.