Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.
The following versions of igloohome Smart Lock Mobile Application are affected:
Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581)
Vendor
Equipment
igloohome
igloohome Smart Lock Mobile Application
Inclusion of Sensitive Information in Source Code
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Singapore
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
igloohome Smart Lock Mobile Application
MitigationFor more information, contact igloohome (info@igloohom...
Read the full advisory on CISA →