A security researcher, known as tokay0, has uncovered a vulnerability in Shark robot vacuums. The flaw enables unauthorized control of devices across an Amazon Web Services (AWS) region using certificates obtained from a rogue unit. Despite being reported to SharkNinja in March, the issue remains unpatched.
The vulnerability is due to an over-permissive AWS IoT policy, which allows a certificate from a single vacuum to authenticate across the network. This enables the execution of root commands and facilitates access to live camera feeds, stored home maps, and plaintext Wi-Fi credentials. The commands operate through the Exec_Command field in a device's AWS state document.
This unpatched flaw presents significant privacy concerns for Shark vacuum users. Without a patch from SharkNinja, users' personal data, including home layouts and network credentials, remains vulnerable to potential attackers. The breach poses risks due to its ability to compromise a user's home security.
Although the researcher only tested this on his own devices, the broad implications across the AWS region highlight an urgent need for a patch. The resolution of this issue rests with SharkNinja, as the vulnerability pertains to the cloud management side rather than individual devices.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A security researcher revealed a flaw in Shark robot vacuums allowing remote root command execution using stolen certificates. This vulnerability endangers user privacy, exposing live camera feeds and stored home data without a patch from SharkNinja as of now.
A researcher disclosed a vulnerability in Shark robot vacuums that can let attackers control devices across an AWS region. The flaw, which has been known to SharkNinja since March, involves unprotected device certificates, allowing unauthorized command execution.