vulnerability Johnson Controls XAAP Android A vulnerability exists in the Johnson Controls XAAP Android application, version 1.53 and earlier. Attackers with physical access to a device could potentially read sensitive data stored locally without encryption. This vulnerability is not exploitable remotely and requires physical access to the device. Johnson Contro… CISA Advisories · Jul 23, 2026 High CVE-2026-34490vulnerabilityandroidcleartext storage