• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Android App Sharing Introduction - Smart Life App, which has a high market share in smart communities, discovered 16 security vulnerabilities!

Smart Life App, which has a high market share in smart communities, discovered 16 security vulnerabilities!

Oliver by Oliver
February 15, 2026 - Updated on August 5, 2026
in Android App Sharing Introduction

Consumer CouncilA press conference held recently pointed out that after testing, the latest Android version (version v4.13.0) of “Smart Life APP”, which has a high market share in Taiwan’s smart communities, still has 16 security vulnerabilities, which may cause users to face three major privacy risks: leakage of personal information, theft of cash flow permissions, and leakage of encrypted information. The Consumer Foundation pointed out that most apps lack a regular random inspection mechanism after obtaining the certification mark, and called on the Ministry of Digital Information and Communications Technology to implement irregular random inspections on high-risk apps to maintain the security of people’s information.
What security vulnerabilities appear in the latest Android version of the “Smart Life” APP? Here is a summary:

 

Consumer CouncilA press conference was held on February 12, 2026 to point out that although the “SmaDay” smart community APP, which claims to have 10,000 communities and 3 million residents, advertised that the application software had passed the MAS L3 highest level information security standard, the Consumer Council and the National Information Security Research Institute conducted two tests on the Android version and found that the smart life APP failed multiple test items. However, Smart Life immediately launched an updated version and issued an official statement after the Consumer Foundation held a press conference.

 

1. What the Consumer Council says:

Consumer Councilpoint out “Smart Life APP“The latest Android version sent for testing (version v4.13.0) has a total of 16 failed items, including 9 failed L1, 4 L2 and 3 L3 items. Users who use this Android version of the App may be exposed to the following security and privacy risks:
A. Personal information leakage (4.1.2.x series):Because the code and log files are not encrypted or sanitized, hackers can easily steal your sensitive information from the temporary storage of your phone.
B. Transaction interception (4.1.3.x/4.1.5.1.3):Without re-verification and anti-overwrite protection during transactions, attackers can lure you in through disguised interfaces, or skim your input actions in the background to steal cash flow permissions.
C. Management Missing (4.1.1.x/4.1.4.x):The privacy declaration is incomplete and the connection identification code (Session) is easy to predict, which increases the risk of account connection being hijacked.

 

The Consumer Foundation calls on the public to reduce their own risks through the following points if they use the “Smart Life APP”:
A. System-level “privilege isolation”:Please go to the settings page of your phone and enable access to the App to the minimum extent possible.
B. Protection against “cash flow and transactions”:Do not bind high-value credit cards, and do not enable the automatic password storage function.
C. Avoid “residue of sensitive data”:It is recommended to clear the “cache data” of the App frequently. If you want to change your phone, you must first click “Logout” in the App and then “Uninstall the App”.

Since the information security defense of mobile apps in Taiwan shows a pathological imbalance of “emphasis on pre-sales and over-emphasis on post-sales,” the Consumer Foundation calls on the Ministry of Data and Development to establish a more complete post-market governance structure, including annual irregular random testing of high-risk (L3 level) apps. If major known vulnerabilities occur in an app within a short period of time after passing the test, those responsible for false laboratory testing should be held accountable. An “App Vulnerability Reporting Platform” similar to CVE should be established to force developers to repair and announce within a time limit. Otherwise, their information security labels should be revoked.

 

2. Smart Life official description:

In response to external concerns and doubts, Smart Life Technology adheres to the principle of dynamic governance of information security and has released Hhotfix updates to version V4.13.1 on February 15 and February 16. Since February 13, it has launched a comprehensive cross-check of dual platforms and dual versions of Android and iOS. In accordance with the continuous improvement mechanism of information security, it has expanded the scope of inspections and strengthened version difference comparison and risk control; we will be externally responsible for verifiable patching and third-party verification results. The actual resolutions currently initiated are as follows:

A. Personal information protection and risk reduction measures:
A comprehensive inventory has been taken and the main communication processes have been strengthened and adopted industry standards.
quasi-transport layer encryption (TLS), and continue to strengthen sensitive data protection mechanisms; at the same time, strengthen the mobile terminalVisual masking of sensitive data and protection settings for screen capture alerts/overwrite risks to reduceInformation exposure risk, the above measures will be retested by a third party to verify the effectiveness of the repair measures.

B. System environment and log management:
Environment separation and permission control enhancement have been started on the system side, and non-
Debug/test settings as necessary, and adjust log levels according to the principle of least privilege to reduce unnecessaryExposed areas, improve the intensity and auditability of environmental control.

C. Transaction security and proactive notification:
Credit card transactions are handled by a PCI DSS compliant third-party cash flow service
Management; this system does not save the complete card number and CVV, but only retains the necessary transaction identification required according to the payment process.Special information (such as token/last four digits/transaction serial number). Transaction notifications and record inquiries have also been optimized.process, improve the transparency and traceability of users’ instant access to transaction information, and increase transaction risksControl intensity.

D.Privacy management:
Implementing the “data minimization” principle, permission necessity checks have been initiated and unnecessary
Remove or adjust permissions to situational requests; and strengthen data collection in the app store simultaneouslyTransparent disclosure to protect users’ right to know.

E.MAS Level 3 version difference check and third-party verification:
In response to the MAS high level proposed by the outside world
Regarding the version differences (v4.1.0 and v4.13.0) of App Information Security Label Level 3, we have started toFor article reproduction and difference comparison, we do not use version differences as an excuse. Instead, we use v4.13.0 (and the patched version) as the main verification benchmark to reproduce each article and clarify the reasons for the differences. At the same time, we entrust a third-party verification company to conduct retests to verify the effectiveness of the patch; the results will be announced in stages according to the verification progress. The patch completion status and verification summary will be announced to the public in stages.

For details on the information security concerns raised by Smart Life APP and the latest processing progress, please seeSmart Life Official Website。

Source: KOCPC Chinese

Tags: Consumer Councilsmart communitySmart Life APP outsourcing

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology