It was recently revealed that a security loophole within Google Home speakers allowed hackers to snoop on conversations.
Kunze notified Google in March 2021 and later published the technical details about his findings, along with a potential attack scenario, which explained how the flaw could be exploited by an outside actor.
He discovered a flaw that allowed commands to remotely through the application programming interface (cloud API) after setting up a new account using the Google Home app.
Serious Loophole Allowed Hackers to Access Smart Appliances and Speakers
Kunze noted that if a hacker got within wireless proximity of a speaker device, even without access to the Wi-Fi network that it was connected to, they could discover a user’s Google Home system.After a user account is created, an actor could then access the user’s setup mode, install a different Google account, and then re-connect it to that unsuspecting person’s Wi-Fi network.
Once a hacker managed to connect their own account to the Google Home speaker, they would have access to the smart devices in the victim’s home by initiating a phone call via the speaker, giving them the ability to hijack appliances, set up scheduled routines, and play music.
Google Update Addresses the Security Bug
Google has since prevented the ability to remotely add an account to a Google Home speaker with a patch that included a new invite-based system to handle account links, blocking any attempts by individuals not added on Home.Phone call security was also fixed as well, with added protection to prevent remote initiation through the scheduled routine system.
Google’s smart displays now have an improved setup network that requires a QR code to log in, allowing it to be protected with WPA2, meaning that a hacker would need physical access to a device to connect their account.
Kunze said that Google Nest and Home devices were, for the most part, rather secure and did not offer a lot of attack vectors and that the vulnerabilities he discovered were pretty subtle.
Other than phone call privacy, he said that the most an attacker could do was to change some basic user settings.
The Epoch Times reached out to Google for comment.