logo

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

ID: f10b3de9-1f87-5ebe-b315-c11e272f2d42

STIX ID: report--f10b3de9-1f87-5ebe-b315-c11e272f2d42

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

A researcher (tokay0) discovered that some SharkNinja robot vacuums use device certificates with an overly permissive AWS IoT policy that permits publish/subscribe to $aws/things/*; with a certificate extracted from a device an attacker can update other devices' shadows to set Exec_Command and achieve remote root command execution, camera access, drive control, and plaintext Wi‑Fi extraction. The flaw is fixed server-side by replacing the policy with a scoped version, but months after disclosure SharkNinja had not applied the remediation; the researcher observed ~1.5M unique serials in one region and ~673k devices responding to Exec_Response, indicating broad potential impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.