Cybersecurity 2 h agoAdd to bookmarks

A researcher claims to have alerted SharkNinja as early as March about a vulnerability that allows remote control of Shark robot vacuum cleaners, access to their camera, and the exfiltration of sensitive data. Patches are still awaited.
According to Journal du Geek, a researcher has identified a vulnerability affecting robot vacuum cleaners from the brand SharkNinja (a well-established consumer brand in North America and Europe). Exploitation would allow an attacker to:
The researcher claims to have alerted the manufacturer as early as March 2026. Several months later, the patches remain partial or absent depending on the models.
The article does not detail the exhaustive list of affected references. As of the date we are writing, it is therefore necessary to consider that the entire Shark connected range is potentially concerned, pending an official advisory from SharkNinja specifying the vulnerable firmwares and the available patches.
No CVE identifier has been made public as of this date.
This incident fits into a well-documented continuum:
For users of connected Shark robots, pending an official patch:
No active exploitation documented in the wild yet - but a patch delay that approaches four months despite a responsible alert. If the case escalates, it could reignite the debate, latent in Europe, on the obligation of a SBOM and a maximum patching deadline for consumer connected objects, as provided for by the Cyber Resilience Act by 2027.
Article produced by artificial intelligence, reviewed under human editorial control.