discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Johnson Controls XAAP Android

A vulnerability in Johnson Controls XAAP Android allows an attacker to obtain confidential information from the device. The affected versions are XAAP Android <1.53.

By CISA·Jul 23·cisa.gov·2 min read

Intelligence analysis by Llama

Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Users can also restrict physical access to devices running the XAAP Android application.

Why it matters

This vulnerability could result in an attacker obtaining confidential information from the device, which could have significant consequences for the security of industrial control systems.

Imagine you have a secret message on your phone that an attacker can read if they have your phone. This is what's happening with the Johnson Controls XAAP Android vulnerability. The company is telling users to update their app to fix the problem and to keep their phones safe.

Analysis

A Cleartext Storage Weakness

A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. This vulnerability allows an attacker with physical access to the device to read the stored data in plaintext.

Why This Matters

This vulnerability is significant because it allows an attacker to obtain confidential information from the device. The affected versions of Johnson Controls XAAP Android are XAAP Android <1.53. Users can update the application to version 1.53 or later to fix this vulnerability.

Mitigation Strategies

Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. They also recommend users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. Additionally, users can implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. Finally, users should avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.

Conclusion

In conclusion, this vulnerability is significant and users should take immediate action to update their XAAP Android applications and implement mitigation strategies to prevent exploitation.

Key points

  • A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption.
  • The affected versions of Johnson Controls XAAP Android are XAAP Android <1.53.
  • Users can update the application to version 1.53 or later to fix this vulnerability.
  • Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.
  • Users should ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.
The Upside

If users update their XAAP Android applications to version 1.53 or later and implement mitigation strategies, they can prevent exploitation of this vulnerability and keep their devices secure.

The Downside

If users do not update their XAAP Android applications and implement mitigation strategies, they may be vulnerable to exploitation of this vulnerability, which could result in an attacker obtaining confidential information from the device.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecurityindustrial-control-systemsvulnerabilitycleartext-storageandroidjohnson-controls

Author

CISA

Intelligence analysis by

Llama

Published

Jul 23, 2026

Source

cisa.gov

Share

Topics

securityindustrial-control-systemsvulnerabilitycleartext-storageandroidjohnson-controls

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.