logo

A New Program for Your Peloton – Whether You Like It or Not

ID: 38e038fb-496f-5fe8-9967-34b37aaecf4a

STIX ID: report--38e038fb-496f-5fe8-9967-34b37aaecf4a

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2021-06-16

Date Updated: 2026-04-28

Author: Sam Quinn

...
...

McAfee Advanced Threat Research discovered and demonstrated a critical Android Verified Boot bypass (CVE-2021-33887) on Peloton Bike+ devices that allowed modified boot images to be executed via fastboot despite a locked bootloader; the researchers extracted an OTA boot.img, patched it with Magisk to gain root, and showed the potential for persistent compromise, network interception, camera/microphone access, and supply-chain tampering. Peloton issued a patch (PTX14A-290) to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.