discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Johnson Controls XAAP Android

A vulnerability in Johnson Controls XAAP Android allows an attacker to obtain confidential information from the device. The affected versions are XAAP Android <1.53.

By CISA·Jul 23·cisa.gov·2 min read

Intelligence analysis by Llama

Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Users can also restrict physical access to devices running the XAAP Android application.

Why it matters

This vulnerability could result in an attacker obtaining confidential information from the device, which could have significant consequences for the security of industrial control systems.

Imagine you have a secret message on your phone that an attacker can read if they have your phone. This is what's happening with the Johnson Controls XAAP Android vulnerability. The company is telling users to update their app to fix the problem and to keep their phones safe.

Analysis

A Cleartext Storage Weakness

A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. This vulnerability allows an attacker with physical access to the device to read the stored data in plaintext.

Why This Matters

This vulnerability is significant because it allows an attacker to obtain confidential information from the device. The affected versions of Johnson Controls XAAP Android are XAAP Android <1.53. Users can update the application to version 1.53 or later to fix this vulnerability.

Mitigation Strategies

Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. They also recommend users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. Additionally, users can implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. Finally, users should avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.

Conclusion

In conclusion, this vulnerability is significant and users should take immediate action to update their XAAP Android applications and implement mitigation strategies to prevent exploitation.

Key points

  • A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption.
  • The affected versions of Johnson Controls XAAP Android are XAAP Android <1.53.
  • Users can update the application to version 1.53 or later to fix this vulnerability.
  • Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.
  • Users should ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.
The Upside

If users update their XAAP Android applications to version 1.53 or later and implement mitigation strategies, they can prevent exploitation of this vulnerability and keep their devices secure.

The Downside

If users do not update their XAAP Android applications and implement mitigation strategies, they may be vulnerable to exploitation of this vulnerability, which could result in an attacker obtaining confidential information from the device.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecurityindustrial-control-systemsvulnerabilitycleartext-storageandroidjohnson-controls

Author

CISA

Intelligence analysis by

Llama

Published

Jul 23, 2026

Source

cisa.gov

Share

Topics

securityindustrial-control-systemsvulnerabilitycleartext-storageandroidjohnson-controls

Related

More from this desk

Oct 10·krebsonsecurity.com

FBI Arrests Founder of Ransomware Negotiation Firm

FBI arrests co-founder of ransomware negotiation firm in connection with ShinyHunters hacking group investigation.

Oct 9·bleepingcomputer.com

Hackers Abuse Google Ads and Bing Redirects to Push Claude ClickFix Attacks

Hackers use Bing search result redirects in Google ads to trick users into downloading fake Claude installers that deliver ClickFix attacks. The technique appears to evade security checks by using Bing's trusted domain as the ad destination.

Oct 9·thehackernews.com

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers found malicious GitHub Actions workloads injected into over 340 repositories, compromising two high-profile open-source maintainer accounts.

Oct 9·thehackernews.com

FBI Arrests Another ShinyHunters Suspect, Reports Involvement in Jobs Portal Hack

FBI arrests another ShinyHunters suspect involved in hacking the FBI's jobs portal and stealing sensitive data.