Hackers Hijack Kids' Smartwatch to Track and Spy on Reporter

5 hours ago
Hackers Hijack Kids' Smartwatch to Track and Spy on Reporter

A WIRED reporter was remotely tracked, photographed, and listened to via a child's smartwatch, demonstrating severe security flaws in popular GPS-enabled devices. Security researchers Vangelis Stykas and Felipe Solferini showcased how easily they could exploit the cheap gadget, originally intended for parental tracking.



The test began with the reporter donning a lavender and pink smartwatch. As he commuted to work, Stykas, who had shipped the watch, revealed he was already monitoring the reporter's location. While the watch's GPS was malfunctioning, it was still transmitting Wi-Fi network identifiers, allowing Stykas to pinpoint the reporter's exact location. Once the reporter reached the WIRED office, Stykas used the watch's camera to take silent photos and its microphone to capture audio, with no indication to the wearer that it was being compromised.



The smartwatch, costing less than $30 and made by an obscure Chinese manufacturer, runs on an online platform used by dozens of other brands. Stykas and Solferini discovered that over 70 GPS-enabled watches and car accessories they analyzed rely on just three main supply chains, all exhibiting significant security vulnerabilities. These flaws, such as a lack of authentication, allow for unauthorized access, location tracking, message interception, and even silent eavesdropping and photo capture.



The researchers plan to present their findings at the Black Hat cybersecurity conference, highlighting that millions of children's devices are vulnerable to exploitation. They've been warning companies about these issues for months. While one platform, SETracker, claims to have fixed its issues, the researchers remain uncertain. Other platforms, SinoTrack and NewGPS2012, did not respond to requests for comment, and their vulnerabilities appear to persist.



Despite years of warnings from cybersecurity experts about the dangers of cheap GPS devices, many brands continue to use insecure platforms. Stykas and Solferini emphasize that the diversity of brands is often an illusion, with many products sharing the same vulnerable backend infrastructure. This means a flaw in one platform can affect dozens of consumer brands simultaneously, leaving users unaware of the true risks.


China's Kimi K3 AI Escapes Sandbox During Security Test
Previous
China's Kimi K3 AI Escapes Sandbox During Security Test
Next
Hackers Hijack Kids' Smartwatch to Track and Spy on Reporter
Hackers Hijack Kids' Smartwatch to Track and Spy on Reporter