Johnson Controls Patches XAAP Android Cleartext Storage Flaw
The vulnerability requires local access or device compromise, not network attack; version 1.53 closes it.
TL;DR
CISA published an advisory for CVE-2026-34490, a cleartext storage vulnerability in Johnson Controls' XAAP Android application affecting versions below 1.53. The flaw stores application data locally without encryption, readable by anyone with physical access to the device or through a separate compromise, no network vector exists. Critical manufacturing sites running XAAP Android should update to version 1.53, which contains the fix. CVSS 3.1 base score is 3.3 (LOW).
CISA published ICSA-26-204-02 on July 23, republishing Johnson Controls' disclosure of CVE-2026-34490, a cleartext storage weakness in the XAAP Android application used in fire solutions. Versions below 1.53 store application data locally without encryption. An attacker who gains physical access to the device, or who compromises it through an unrelated flaw, can read that data in plaintext.
The vulnerability carries a CVSS v3.1 base score of 3.3 (LOW) and a CVSS v4.0 score of 4.8 (MEDIUM). The attack vector is strictly local, meaning no network access is required for exploitation and no remote attack path exists. That limits the practical exposure considerably, though for defense contractors and primes running XAAP Android in critical manufacturing environments, the plaintext data could include operational details worth protecting.
Johnson Controls' fix is straightforward: update XAAP Android to version 1.53 or later. The vendor also recommends restricting physical access to devices, enabling Android device encryption and screen locks, deploying MDM for policy enforcement and remote wipe, and avoiding rooted or jailbroken devices in production. What the advisory doesn't address is whether XAAP on iOS or other platforms shares the same cleartext storage behavior. The disclosure is Android-only. Organizations running XAAP across mixed mobile fleets should verify exposure on non-Android deployments independently.
Published ·Deep Fathom