Amazon Alexa can be hijacked via commands from own speaker

Without a critical update, Amazon Alexa devices could wake themselves up and start executing audio commands issued by a remote attacker, according to infosec researchers at Royal Holloway, University of London. By exploiting a now-patched vulnerability, a malicious person with access to a smart speaker could broadcast commands to itself or to other smart speakers nearby, allowing said miscreant to start “smart appliances within the household, buy unwanted items, tamper [with] linked calendars and eavesdrop on the [legitimate] user.”

Read full article on The Register

 


Date:

Categorie(s):

Tag(s):