CloudPets Woes Worsen With News Of A Bluetooth Exploit

 

If having their database leaked and ransomed isn’t enough, CloudPets has a new problem to worry about. Their toys can be pwned remotely from a webpage via the Bluetooth Web API which is not exactly secure says Context Information Security who put out a report on the matter.

Here’s how the exploit works. Create a webpage to connect to CloudPets toy via Bluetooth. The browser opening the page has to be within Bluetooth range of the CloudPets toy for it to work. You must also allow the browser to pair with the toy. Then start recording from the toys built-in microphone. You can also play sounds through it. A proof of concept webpage is online, and code is on GitHub which means evil doers will have real exploit pages online shortly.

Here’s a video of the pwnage in action:

Clearly CloudPets doesn’t care about the security of their users. If you have one of these toys, put it in the rubbish bin right now. It’s clearly insecure and you should not have it anywhere near your kids.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading