Johnson Controls XAAP Android
Summary
Johnson Controls XAAP Android versions before 1.53 contain a cleartext storage weakness (CWE-312, where sensitive information is stored without encryption), allowing an attacker with physical access to the device to read application data in plaintext. The vulnerability has a low severity CVSS score of 3.3 and does not require network access.
Solution / Mitigation
Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Additionally, Johnson Controls recommends restricting physical access to devices, ensuring devices have up-to-date Android OS versions with device encryption and screen lock protections enabled, implementing a Mobile Device Management (MDM) solution to enforce security policies including encryption and remote wipe capabilities, and avoiding rooting or jailbreaking devices in production environments.
Classification
Original source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
First tracked: July 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%