logo

Robot Vacuum Flaw Could Give Hackers Control Over Millions of Home Devices

ID: be103218-e2c1-5aa8-b1e8-12885b3edbf8

STIX ID: report--be103218-e2c1-5aa8-b1e8-12885b3edbf8

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Paul Roberts

...
...

Research published by security researcher tokay0 describes a cloud-authorization flaw in SharkNinja robot vacuums that allowed overly permissive AWS IoT device certificates to be reused across devices, enabling remote code execution and access to cameras, stored home maps, and Wi‑Fi credentials; the researcher observed communications from ~1.5 million devices and ~673,000 exposing the vulnerable command handler, and SharkNinja reportedly issued a fix on July 20th after coordinated disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.