CVE-2023-24080: Chamberlain Myq

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.

Affected products

Published 2023-02-21. Last modified 2026-07-09.