Unknown · Home Assistant · CVE-2026-55844
**Name of the Vulnerable Software and Affected Versions**
Home Assistant versions prior to 2025.5.0
**Description**
The iOS companion app fails to respect the SSID allowlist for internal networks. While the app typically uses the Service Set Identifier (SSID)—the public name of a wireless network—to determine when to use the internal URL, it incorrectly falls back to the internal URL when no other URL is available. This behavior can lead to the exposure of the user's authentication token when the device is connected to an insecure network.
**Recommendations**
Update to version 2025.5.0.