Amazon Echo vulnerable to old security flaws

(Image credit: Amazon)

Security experts have warned that Amazon Echo devices could still be susceptible to a range of flaws.

A team known as Flouroacetate were able to hack into an Amazon Echo device due to shortcomings in the security software used to protect the device.

Hackers exploiting this "patch gap" would be able to overload an affected device to hijack the Echo, and possible even then gain access to a victim's home network.

Full control

The findings were enough for the Fluoroacetate team to win the Pwn2Own hacking contest, which is held every year to highlight security flaws in modern-day devices.

They used an Amazon Echo Show 5, which as an older release was particularly at risk due to not being eligible for some of the latest security patches sent out by Amazon.

In this case, the device was found to be using an older edition version of Google's Chromium browser engine, which had been forked during its development. The Fluoroacetate team were able to target this outdated code through the use of an integer overflow JavaScript bug and a malicious Wi-Fi network to hijack the device and take "full control".

The team, who netted $60,000 in bug bounties as their prize, shared the findings with Amazon, which has said it will be "investigating" the flaws and would take "appropriate steps" to protect its devices.

Via TechCrunch

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news