[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fodV3oLRawNic53SVEGPVFFRQmXLmvnK0sbgF1ndBmGA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"5d3c40d9-4d29-420d-a879-31d0e62be633","johnson-controls-xaap-android-app-stores-sensitive-data-in-cleartext","a70d5b0b-6c01-41f6-bd58-babbfca4adb3","Johnson Controls XAAP Android App Stores Sensitive Data in Cleartext","CVE-2026-34490 reveals that Johnson Controls' XAAP Android application stored sensitive data in plaintext, meaning any attacker with physical access to the device could read confidential application data without any decryption effort. This is a fundamental data protection failure — encryption at rest is a baseline security requirement for mobile applications handling sensitive information. The vulnerability affects all versions prior to 1.53, meaning devices that are not promptly updated remain exposed. In operational technology (OT) and building management contexts, where mobile apps often interface with critical infrastructure, such exposures can have serious downstream consequences.","**Immediate Actions:**\n- Update all XAAP Android installations to version 1.53 or later as directed by Johnson Controls.\n- Audit which devices have the XAAP app installed and enforce physical access restrictions on those devices immediately.\n\n**Long-term Improvements:**\n- Enforce encryption-at-rest policies for all mobile applications handling sensitive or operational data through MDM (Mobile Device Management) solutions.\n- Integrate mobile application security testing (MAST) into the software development lifecycle to catch cleartext storage issues before release.\n- Establish a mobile application inventory and patching cadence to ensure timely updates across all managed devices.\n\n**Detection Measures:**\n- Deploy MDM solutions to monitor app versions and flag devices running outdated or non-compliant software.\n- Conduct periodic penetration tests on mobile applications used in OT\u002Fbuilding management environments to proactively identify data exposure vulnerabilities.",[12,13,14,15,16,17,18,19],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 7: Continuous Vulnerability Management","NIST SP 800-124: Guidelines for Managing the Security of Mobile Devices","NIST SC-28: Protection of Information at Rest","NIST SI-2: Flaw Remediation","OWASP Mobile Top 10: M9 - Insecure Data Storage","GDPR Article 32: Security of Processing (encryption of personal data)","IEC 62443-3-3: System Security Requirements (for OT environments)","published","2026-07-23T20:20:55.795634+00:00","2026-07-23T20:20:55.495+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-204-02","johnson-controls-xaap-android-6072f3","Johnson Controls XAAP Android",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]