CVE-2026-64823 is a cross-site scripting vulnerability in Home Assistant Core before version 2026.5.4. The vulnerability exists in the Shelly integration's async_get_media_image() method, which allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against an image-only allowlist. This vulnerabilit [truncated]
## Summary Home Assistant Companion apps for Android (prior to 2026.4.4) and iOS (prior to 2026.4.1) contain a cross-origin JavaScript bridge exposure vulnerability. The apps expose native bridge objects (`window.externalApp` on Android; `webkit.messageHandlers.getExternalAuth`, `revokeExternalAuth`, and `externalBus` on iOS) to all frames within the in-app WebView, including cross-origin iframes. Combine [truncated]