Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Security experts report serious Google Home vulnerabilities receive $107500 reward from Google

Shulou Source: shulou.com Published: 2023-11-24 13:46:21 10月03日 Update

CTOnews.com, Dec. 30 (Xinhua)-- Security researcher Matt Kunze reported serious vulnerabilities in Google Home to Google last year and recently received a hefty reward of $107500 (about 749000 yuan) from Google.

CTOnews.com learned that a vulnerability has been discovered on Google Home smart audio devices that allows attackers to install backdoor accounts for remote control and activate microphones to monitor user conversations. Kuntz disclosed all the technical details of the vulnerability and how to exploit it earlier this week.

Kuntz scanned the Nmap and found the port of Google Home's local HTTP API. So he sets up a proxy to capture encrypted HTTPS traffic, hoping to hijack the user's authorization token.

The researchers found that adding a new user to the target device requires two steps, requiring the device name, certificate, and a "cloud ID" from its local API. With this information, they can send link requests to Google servers.

More worryingly, the researchers found a way to abuse the "call [phone number]" command by adding it to a malicious routine that activates the microphone at a specified time, calls the attacker's number, and sends a real-time microphone feed.

Kuntz identified these issues in January 2021 and sent more details and PoC in March 2021. Google fixed all the problems in April 2021.

Tags: Vulnerabilities Kuntz users devices microphones mics researchers messages numbers attackers activations researchers questions attacks bounties worrying two RMB tokens Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno macOS Linux MySQL Xiaomi Docker