US government says security flaw in Chirp Systems’ app lets anyone remotely control smart home locks

US government says security flaw in Chirp Systems’ app lets anyone remotely control smart home locks

a week ago
Anonymous $6hYC3Wwiad

https://techcrunch.com/2024/04/22/cisa-chirp-systems-remotely-unlock-smart-locks/

A vulnerability in a smart access control system used in thousands of U.S. rental homes allows anyone to remotely control any lock in an affected home. But Chirp Systems, the company that makes the system, has ignored requests to fix the flaw.

U.S. cybersecurity agency CISA went public with a security advisory last week saying that the phone apps developed by Chirp, which residents use in place of a key to access their homes, “improperly stores” hardcoded credentials that can be used to remotely control any Chirp-compatible smart lock.