discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Johnson Controls XAAP Android

A vulnerability in Johnson Controls XAAP Android allows an attacker to obtain confidential information from the device. The affected versions are XAAP Android <1.53.

By CISA·Jul 23·cisa.gov·2 min read

Intelligence analysis by Llama

Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Users can also restrict physical access to devices running the XAAP Android application.

Why it matters

This vulnerability could result in an attacker obtaining confidential information from the device, which could have significant consequences for the security of industrial control systems.

Imagine you have a secret message on your phone that an attacker can read if they have your phone. This is what's happening with the Johnson Controls XAAP Android vulnerability. The company is telling users to update their app to fix the problem and to keep their phones safe.

Analysis

A Cleartext Storage Weakness

A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. This vulnerability allows an attacker with physical access to the device to read the stored data in plaintext.

Why This Matters

This vulnerability is significant because it allows an attacker to obtain confidential information from the device. The affected versions of Johnson Controls XAAP Android are XAAP Android <1.53. Users can update the application to version 1.53 or later to fix this vulnerability.

Mitigation Strategies

Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. They also recommend users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. Additionally, users can implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. Finally, users should avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.

Conclusion

In conclusion, this vulnerability is significant and users should take immediate action to update their XAAP Android applications and implement mitigation strategies to prevent exploitation.

Key points

  • A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption.
  • The affected versions of Johnson Controls XAAP Android are XAAP Android <1.53.
  • Users can update the application to version 1.53 or later to fix this vulnerability.
  • Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.
  • Users should ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.
The Upside

If users update their XAAP Android applications to version 1.53 or later and implement mitigation strategies, they can prevent exploitation of this vulnerability and keep their devices secure.

The Downside

If users do not update their XAAP Android applications and implement mitigation strategies, they may be vulnerable to exploitation of this vulnerability, which could result in an attacker obtaining confidential information from the device.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecurityindustrial-control-systemsvulnerabilitycleartext-storageandroidjohnson-controls

Author

CISA

Intelligence analysis by

Llama

Published

Jul 23, 2026

Source

cisa.gov

Share

Topics

securityindustrial-control-systemsvulnerabilitycleartext-storageandroidjohnson-controls

Related

More from this desk

Jul 23·bleepingcomputer.com

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan uses an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.

Jul 23·bleepingcomputer.com

Australian energy provider Origin says data breach exposes client data

Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to i…

Jul 23·bleepingcomputer.com

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A Bing malvertising campaign pushed a fake Claude desktop app that delivered SectopRAT malware, compromising at least 29 organizations in two days. The lure abused a legitimate Anthropic Claude.ai Artifact as its landing page.

Jul 23·thehackernews.com

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes. The group targeted Western government and commercial organizations through Zimbra since at least July 2025.