logo

Update: Hello Barbie Fails Another Security Test

ID: 6378280f-6b8a-516d-9b08-fb487228c239

STIX ID: report--6378280f-6b8a-516d-9b08-fb487228c239

Feed Name: Security Ledger

Threat Score
50/100

Date Published: 2015-12-04

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Executive summary: Security researchers from Bluebox and an independent analyst found multiple vulnerabilities in Mattel/ToyTalk’s Hello Barbie ecosystem — a hardcoded P12 certificate password in the mobile apps, an unsecured initial setup hotspot allowing wireless spoofing and MITM attacks, and servers supporting weak SSLv3 ciphers susceptible to POODLE — which could enable credential theft or interception of recorded audio; ToyTalk has issued patches and used OTA updates to remediate the reported flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.