Junglewise Threat Intelligence

CVE-2026-36028: Code 27 Companion Hub kiosk bypass via factory reset

CVE-2026-36028 · Severity: info · CVSS 0 · Published 2026-07-08

Executive brief

The Code 27 3D Companion Hub, a desktop AI device, contains a flaw that allows anyone with physical access to bypass its security restrictions. By performing a factory reset through the device's recovery menu, an unauthorized user can remove the 'kiosk' mode that normally limits what the device can do. This allows full access to the underlying operating system, potentially compromising the device's intended privacy and security controls.

Technical details

The Code 27 3D Companion Hub (running Android 12 on Rockchip RK3588S) fails to properly secure its recovery environment against unauthorized factory resets. An attacker with physical access can boot the device into the Android recovery menu by using a specific hardware button combination (Power + Volume). From this menu, the attacker can trigger a factory reset, which wipes the device's configuration and effectively removes the kiosk mode restrictions intended to lock down the user interface. This allows the attacker to bypass the intended security boundary and gain unrestricted access to the standard Android operating system environment. As of the advisory date, this vulnerability remains unpatched.

Affected products

  • Code 27 3D Companion Hub 1.2.0

Timeline

  • 2026-07-08: advisory: NVD publication date

References