Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

An unpatched Shark vacuum flaw could put your smart home at risk

Дата публикации: 20-07-2026 21:57:12

A newly disclosed SharkNinja vulnerability could let attackers access robot vacuum cameras, home maps, and Wi-Fi passwords through an unpatched cloud security flaw affecting millions of devices.

Основное содержимое страницы с новостью.

The vulnerability affects SharkNinja robot vacuums and stems from a misconfigured cloud security policy rather than a firmware bug.
Shark RV2320S Matrix Self-Emptying Robot Vacuum Featured Shark

Robot vacuums are supposed to clean the house. Turns out this one was mapping it for strangers. Security researchers have disclosed a critical vulnerability affecting SharkNinja’s cloud-connected robot vacuums that could allow attackers to remotely access sensitive information, including live camera feeds, home maps, Wi-Fi passwords, and even execute commands on affected devices. More concerningly, the issue reportedly remains unpatched despite being responsibly disclosed to SharkNinja months ago.

How can a vacuum become a spy?

The flaw was discovered by security researcher tokay0, who reverse-engineered a Shark RV2320EDUS robot vacuum. According to the research, the device contains an AWS IoT certificate that is allowed to communicate with other Shark devices in the same AWS region, rather than being restricted to its own device. That overly broad cloud policy effectively allows a certificate extracted from one vacuum to interact with many others.

Shark RV2320S Matrix Self-Emptying Robot Vacuum MainShark RV2320S Shark

If exploited, an attacker could remotely issue commands to vulnerable vacuums, access camera feeds, download maps of a user’s home, retrieve Wi-Fi passwords reportedly stored in plaintext, and potentially gain a foothold on the victim’s local network. The researcher observed more than 1.5 million unique Shark devices in a single AWS region over 24 hours, with around 673,000 devices responding in a way that suggested support for remote command execution. While that doesn’t confirm every one of those devices is exploitable, it indicates the issue could affect a very large number of products.

To be fair, the attack isn’t as simple as someone hacking a vacuum over the internet. To begin with, an attacker first needs physical access to a compatible Shark vacuum in order to extract its embedded certificate through a debug interface. That significantly raises the barrier to entry, making the attack more likely to be carried out by skilled researchers or determined attackers rather than opportunistic hackers.

The bad news is that once such a certificate has been extracted, the rest of the attack can take place remotely through SharkNinja’s cloud infrastructure. According to the researcher, the underlying problem lies in the company’s cloud-side AWS IoT policy, meaning users can’t fix it themselves with a firmware update. The required mitigation has to be implemented by SharkNinja on its servers.

What should Shark owners do?

The researcher says the vulnerability was first disclosed to SharkNinja in March 2026, but no patch had been released at the time of publication. Reports also note that there is currently no CVE identifier assigned for the issue, and SharkNinja has yet to publicly announce a fix.

Shark RV2320S Mapping Home HouseShark

Until the company addresses the problem, users who don’t rely on smart features may want to consider disconnecting their robot vacuum from Wi-Fi or disabling remote functionality to reduce the attack surface. It’s a temporary workaround rather than a true fix, but since this is a cloud-side vulnerability, the responsibility ultimately lies with the manufacturer.

Varun Mirchandani

Varun is an experienced technology journalist and editor with over eight years in consumer tech media. His work spans…

Google Home’s Interactive Storytime feature has me wondering who actually asked for this

Google Home gets interactive AI storytime, smarter alarms, and broader camera support.

Computer, Electronics, Tablet Computer

Google Home's latest update introduces several new features, including Gemini-powered Interactive Storytime. While I’m not sure who asked for the feature, it lets families build original stories about specific topics on the fly, instead of just listening to a known story. 

So what's the big new feature here?

Read more

Proxima wants to move blood tests into the home, and it has cleared an important early hurdle

The portable analyzer delivers blood-count results in about 20 minutes, but its promise depends on transparent clinical data

Furniture, Table, Desk

Algocyte’s Proxima is designed to run blood-count tests from a small finger-prick sample and send the results to a clinician in about 20 minutes. For patients who need frequent monitoring, that could mean fewer trips to a clinic or laboratory.

The device has also moved beyond the concept stage. Proxima carries UK conformity credentials, while Algocyte operates under a certified medical-device quality system. Those steps give the project more weight than a prototype shown at a launch event.

Read more

Remember Samsung’s Ballie home robot? It may finally be inching closer to reality

Leaked app wireframes give the strongest hint yet that Samsung's Ballie home robot, first shown at CES 2020, might still be headed toward an actual release.

Samsung Ballie robot in a room next to a dog feeder.

Samsung's rolling home robot has been the industry's longest-running "will it ever actually ship" joke, and I'll admit I'd mostly given up on it. Now, there's finally a glimmer of hope.

Samsung first unveiled Ballie as a concept at CES 2020. Then, it showed it as a significantly upgraded version four years later. However, the company never confirmed a release date or committed to releasing it at all. 

Read more

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Злоумышленники могут взламывать роботы-пылесосы Shark и удаленно управлять ими016.3320-07-2026
2Атакована недоисправленная уязвимость в Windows-2609-07-2026
3Seven iPhone models compromised by major security breach... is yours on the list?-3720-06-2026
4Millions of iPhones at risk of devastating 'DarkSword' cyberattack: 'Act NOW'-2619-03-2026
5В чипсетах Intel обнаружили неустранимую уязвимость0005-03-2020
6FBI cyber unit exposes three signs your smart devices have been secretly hijacked0521-03-2026
7Kritische Sicherheitslücken bei Yarbo-Mährobotern entdeckt-3710-06-2026
8New U-Boot flaws could enable stealthy firmware attacks-2710-07-2026
9Wired: уязвимости в AirPlay позволяют хакерам взломать устройство0030-04-2025

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 9.33. Источник: www.digitaltrends.com.