Our takeCISA advisory on igloohome Smart Lock Android app 3.2.3 (CVE-2026-16581, CVSS 5.3): flaw lets unauthorized actors reach backend services. Update if you use it; most smaller shops don't run these locks and can skip this.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_ics · cisa_ics
What this means for you — Security leader:If your sites use igloohome smart locks managed via the Android app, update past 3.2.3 and confirm the app cannot reach backend functions or services without authorization. Treat this as an access-control risk, not only a mobile patch item.
What this means for you — Lean IT orgs:If you use the igloohome Android app at version 3.2.3, update it now from the store. If you don’t run these locks, you can ignore this.
What this means for you — MSP:Inventory clients for igloohome Smart Lock Android app 3.2.3 and push the update. Flag any site where app-level access could reach lock functions or backend services.
What this means for you — Researcher:CISA ICSA-26-209-06 covers igloohome Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581, CVSS 5.3): unauthorized access to functions or backend services. Public summary is thin on root cause and exploit preconditions.