Shark vacuum cleaners: a flaw turns robots into rolling spies - SharkNinja is slow to patch

Cybersecurity 4 h agoAdd to bookmarks

Shark vacuum cleaners: a flaw turns robots into rolling spies - SharkNinja is slow to patch
Illustration : Momiji Shirogane

A researcher claims to have alerted SharkNinja as early as March about a vulnerability that allows remote control of Shark robot vacuum cleaners, access to their camera, and the exfiltration of sensitive data. Patches are still awaited.

The facts

According to Journal du Geek, a researcher has identified a vulnerability affecting robot vacuum cleaners from the brand SharkNinja (a well-established consumer brand in North America and Europe). Exploitation would allow an attacker to:

  • remotely control the robot;
  • activate the onboard camera;
  • exfiltrate data (mapping of the interior of the dwelling, potentially Wi-Fi identifiers or session tokens, depending on the models).

The researcher claims to have alerted the manufacturer as early as March 2026. Several months later, the patches remain partial or absent depending on the models.

Who is affected?

The article does not detail the exhaustive list of affected references. As of the date we are writing, it is therefore necessary to consider that the entire Shark connected range is potentially concerned, pending an official advisory from SharkNinja specifying the vulnerable firmwares and the available patches.

No CVE identifier has been made public as of this date.

Context: Domestic IoT = persistent blind spot

This incident fits into a well-documented continuum:

  • Robot vacuum cleaners now include cameras, LIDAR, microphones and a detailed map of the home - i.e., the ideal user's surveillance data.
  • The time-to-patch of a consumer hardware manufacturer remains much longer than that of a software publisher: several months of delay between responsible disclosure and patch are not exceptional.
  • The AIVD/MIVD report documents how poorly patched IoT is now exploited for intelligence purposes - not just by script kiddies.

What to do now

For users of connected Shark robots, pending an official patch:

  1. Isolate the robot on a guest VLAN (separate Wi-Fi SSID, no access to the rest of the home network);
  2. Cut off the robot's outgoing Internet access if the manufacturer allows a local mode - or block its telemetry addresses at the router level;
  3. Physically cover the camera (sticker) when the robot is not on a mission;
  4. Regularly check the SharkNinja support page for a firmware with a patch.

What to remember

No active exploitation documented in the wild yet - but a patch delay that approaches four months despite a responsible alert. If the case escalates, it could reignite the debate, latent in Europe, on the obligation of a SBOM and a maximum patching deadline for consumer connected objects, as provided for by the Cyber Resilience Act by 2027.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

4 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information