Critical Security Update Released for Homey Hubs

A close-up of a glowing black Homey Pro smart hub on a console, flanked by a soundbar and a Pilea plant.

A sudden email from a smart home manufacturer about a critical security flaw is never pleasant to see in your inbox, but taking quick action keeps your network safe.

What Happened

If you use a Homey smart hub to control your devices, you must check your firmware version today. The company recently sent out an urgent email alert regarding a critical vulnerability discovered in their system by an external security researcher. However, there is a major catch. You will only receive this email if your hub has automatic updates disabled. Because Homey has not posted this alert on their official website yet, many users are completely unaware of the issue.

Why You Should Care

A critical vulnerability means there is a potential open door for someone to access your network. Think of it like accidentally leaving your front door unlocked. Even if you think you have automatic updates turned on, it is crucial to double-check manually. Alert emails often end up lost in spam folders or sent to old email addresses you no longer monitor. While Homey states they have not seen any evidence of hackers actively using this flaw, it is always better to verify your hub is locked down before someone tries the handle.

The Technical Details

The fix is already available. Homey rolled out firmware version 13.4.1, which completely closes this security gap. This update applies to the Homey Pro, the Homey Pro mini, and the server software you might run on your own hardware. Along with the security patch, this update also smooths out connection issues with older Z-Wave devices and squashes some bugs related to the Matter protocol.

How to Update Your Hub

  1. Open the Homey mobile app.
  2. Tap on “More” in the bottom menu.
  3. Select “Settings”.
  4. Tap on “Updates” and choose “Check for Updates”.

Image Credit: Homey