logo

Ski & bike helmets protect your head, not location or voice

ID: b0245d96-0277-509c-9bb0-1e4df775e97b

STIX ID: report--b0245d96-0277-509c-9bb0-1e4df775e97b

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-02-07

Date Updated: 2026-03-24

Author: Ceri Coburn and Joe Blogs

...
...

Researchers discovered that Livall’s ski and bike helmet apps used weak 6-digit group codes and lacked join approvals, allowing attackers to brute-force codes, silently join groups, track users’ real-time locations, and eavesdrop on push-to-talk audio; after a challenging disclosure process and media escalation, Livall implemented stronger alphanumeric join codes, though usability issues and disclosure process concerns remain, with impact spanning the larger bike app user base and smaller ski app cohort.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.