Google Home speakers allowed hackers to snoop on conversations

TL;DR

A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed.Earlier this week, the researcher published technical details about the finding and an attack scenario to show how the flaw could be leveraged.The attack is summarized in the researcher's blog as follows:The researcher published on GitHub three PoCs for the actions above.The PoCs take things a step further from just planting a rogue user and enable spying over the microphone, making arbitrary HTTP requests on the victim's network, and reading/writing arbitrary files on the device.Having a rogue account linked to the target device makes it possible to perform actions via the Google Home speaker, such as controlling smart switches, making online purchases, remotely unlocking doors and vehicles, or stealthily brute-forcing the user's PIN for smart locks."

Like summarized versions? Support us on Patreon!