Johnson Controls XAAP Android
Low RiskCVSS 3.3ICS-CERT ICSA-26-204-02Jul 23, 2026
Johnson Controls
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Johnson Controls XAAP Android versions prior to 1.53 store confidential information (including potential credentials and configuration data) in a way that allows local extraction by someone with physical access to the device. The vulnerability is a local data exposure risk affecting devices not protected by screen locks or encryption.
What this means
What could happen
An attacker with physical access to a device running XAAP Android could read confidential information stored locally on the device, such as configuration data or access credentials used to control facility operations.
Who's at risk
Water and electric utility operators who use Johnson Controls XAAP Android tablets or smartphones to remotely view or manage HVAC systems, building automation, or facility controls. This affects any technician or operator device storing credentials, configuration files, or operational data locally.
How it could be exploited
An attacker must have physical access to an unlocked or inadequately protected Android device running XAAP Android below version 1.53. They could then extract local data files from the application's storage directory without requiring valid credentials.
Prerequisites
- Physical access to an Android device running XAAP Android version 1.52 or earlier
- Device not protected by screen lock or encryption
- XAAP Android application installed and data not adequately secured
Requires physical access to deviceLow complexity exploitationLow CVSS score
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
XAAP Android<1.53Fix available
Remediation & Mitigation
0/7
Do now
0/4HARDENINGEnable full-device encryption on all Android devices running XAAP
HARDENINGEnforce screen lock protection (PIN, biometric, or pattern) on all Android devices running XAAP
HARDENINGRestrict physical access to devices running XAAP Android through secure storage or supervised use
HARDENINGProhibit rooting or jailbreaking of production Android devices running XAAP
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate XAAP Android application to version 1.53 or later
HARDENINGKeep Android OS updated to the latest available version from the device manufacturer
Long-term hardening
0/1HARDENINGDeploy Mobile Device Management (MDM) solution to enforce encryption, application whitelisting, and remote wipe policies
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/2ab24e01-3ea0-40e9-bd61-3946d787c1f3Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.