logo

Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords

ID: 9518ae4c-74c7-5f39-b27f-3fe677040fd4

STIX ID: report--9518ae4c-74c7-5f39-b27f-3fe677040fd4

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

Shark robot vacuums ship with an overly permissive AWS IoT/MQTT policy and embedded device certificates that allow a stolen certificate from one vacuum to publish/subscribe to shadows for many other devices in the same AWS Region. A researcher who extracted a certificate demonstrated the ability to monitor and issue remote commands, potentially exposing cameras, plaintext Wi‑Fi credentials, and home maps; the issue is cloud-side (requires vendor action) and reportedly remains unpatched after more than six months.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.