Code InjectionWeakness · CWE-94

CVE-2026-44698

HIGH · 8.3 CVSS v3.1 Published 2026-05-29
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
90/100
Remediation priority · Urgent
Remotely reachable No privileges

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation of the JavaScript callback identifier allows a cross-origin iframe rendered inside the Companion app to execute arbitrary JavaScript in the Home Assistant frontend's main-frame origin and exfiltrate the signed-in user's access token. This vulnerability is fixed in 2026.4.1 for iOS and 2026.4.4 for Android.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

The Home Assistant Companion apps for iOS and Android expose a JavaScript bridge (window.externalApp on Android, webkit.messageHandlers on iOS) to the in-app WebView. The bridge is incorrectly exposed to all frames including cross-origin iframes, and unsanitized interpolation of JavaScript callback identifiers allows a malicious cross-origin iframe to inject and execute arbitrary JavaScript in the main-frame origin, enabling exfiltration of the signed-in user's access token.

MitigationUpdate Home Assistant Companion apps to version 2026.4.1 or later for iOS, and version 2026.4.4 or later for Android, to patch the vulnerable JavaScript bridge exposure.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
High
Privileges
None
User interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify Home Assistant Companion app installation
    Check your device for the Home Assistant Companion app - on Android look in Settings > Apps for 'Home Assistant', on iOS check the App Library or home screen for the app icon
    Affected if The app is not installed on the device
  2. Check Android app version
    On Android: Go to Settings > Apps > Home Assistant > App info, or tap the app icon in the Play Store to see the version number. The version will be listed as '2026.x.x' or similar
    Affected if The installed version is earlier than 2026.4.4 on Android
  3. Check iOS app version
    On iOS: Go to Settings > Home Assistant, or tap the app in the App Store to view the version. The version will be displayed as '2026.x.x'
    Affected if The installed version is earlier than 2026.4.1 on iOS
  4. Confirm app is in use with WebView
    The vulnerability affects the in-app WebView when loading web content. Open the Home Assistant Companion app and verify it loads the Home Assistant frontend through its embedded browser
    Affected if The app loads the Home Assistant interface through its internal WebView

A user is affected if they have the Home Assistant Companion app installed with version before 2026.4.4 on Android or before 2026.4.1 on iOS, and use the app to access their Home Assistant instance.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Update Home Assistant Companion apps to version 2026.4.1 or later for iOS, and version 2026.4.4 or later for Android, to patch the vulnerable JavaScript bridge exposure.

Recommended fix High confidence

iOS: 2026.4.1+, Android: 2026.4.4+

  1. Open the App Store (iOS) or Google Play Store (Android) on your device
  2. Search for "Home Assistant Companion" or "Home Assistant"
  3. Update the Home Assistant Companion app to version 2026.4.1 or later for iOS
  4. Update the Home Assistant Companion app to version 2026.4.4 or later for Android
  5. Launch the updated app and verify you remain logged in with your access token
  6. Confirm the WebView JavaScript bridge is no longer exposed to cross-origin iframes by testing any third-party integrations loaded in iframes

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation2.0 h
  • Implementation1.0 h
  • Testing3.0 h
  • Review / QA2.0 h
8.0 hours of engineering $1,390
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $2,224.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-44698 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-44698 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data