← All stories
● Covered by 2 sources · 2 reportsMedium impact

Unpatched Flaw in Shark Vacuums Allows Unauthorized Control Across AWS Region

🔄 Updated 77d ago — new reporting from Tom's Hardware
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Flaw allows unauthorized control of Shark vacuums across an AWS region.
  • Exposes live camera, home map data, and plaintext Wi-Fi credentials.
  • Researcher reported flaw to SharkNinja in March.
  • Vulnerability stems from over-permissive AWS IoT policy.
  • No patches have been released by SharkNinja yet.

Unpatched Vulnerability Discovered

A security researcher, known as tokay0, has uncovered a vulnerability in Shark robot vacuums. The flaw enables unauthorized control of devices across an Amazon Web Services (AWS) region using certificates obtained from a rogue unit. Despite being reported to SharkNinja in March, the issue remains unpatched.

Technical Details

The vulnerability is due to an over-permissive AWS IoT policy, which allows a certificate from a single vacuum to authenticate across the network. This enables the execution of root commands and facilitates access to live camera feeds, stored home maps, and plaintext Wi-Fi credentials. The commands operate through the Exec_Command field in a device's AWS state document.

Implications for Privacy

This unpatched flaw presents significant privacy concerns for Shark vacuum users. Without a patch from SharkNinja, users' personal data, including home layouts and network credentials, remains vulnerable to potential attackers. The breach poses risks due to its ability to compromise a user's home security.

Awaiting a Patch

Although the researcher only tested this on his own devices, the broad implications across the AWS region highlight an urgent need for a patch. The resolution of this issue rests with SharkNinja, as the vulnerability pertains to the cloud management side rather than individual devices.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A security researcher revealed a flaw in Shark robot vacuums allowing remote root command execution using stolen certificates. This vulnerability endangers user privacy, exposing live camera feeds and stored home data without a patch from SharkNinja as of now.

A researcher disclosed a vulnerability in Shark robot vacuums that can let attackers control devices across an AWS region. The flaw, which has been known to SharkNinja since March, involves unprotected device certificates, allowing unauthorized command execution.