A New Program for Your Peloton – Whether You Like It or Not
ID: 38e038fb-496f-5fe8-9967-34b37aaecf4a
STIX ID: report--38e038fb-496f-5fe8-9967-34b37aaecf4a
Feed Name: McAfee Labs Blog
McAfee Advanced Threat Research discovered and demonstrated a critical Android Verified Boot bypass (CVE-2021-33887) on Peloton Bike+ devices that allowed modified boot images to be executed via fastboot despite a locked bootloader; the researchers extracted an OTA boot.img, patched it with Magisk to gain root, and showed the potential for persistent compromise, network interception, camera/microphone access, and supply-chain tampering. Peloton issued a patch (PTX14A-290) to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
