A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home.

A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home.

      The vulnerability impacts SharkNinja robot vacuums and is due to a misconfigured cloud security policy instead of a flaw in the firmware.

      Shark robot vacuums are intended for cleaning homes, but it turns out that one was mapping them for outsiders. Security researchers have revealed a significant vulnerability in SharkNinja’s cloud-connected robot vacuums, potentially allowing attackers to remotely access sensitive information, including live camera feeds, home layouts, Wi-Fi credentials, and even execute commands on the affected devices. Alarmingly, the issue remains unresolved despite being responsibly reported to SharkNinja months ago.

      How can a vacuum turn into a spy?

      The vulnerability was identified by security researcher tokay0, who reverse-engineered a Shark RV2320EDUS robot vacuum. The findings indicate that the device has an AWS IoT certificate allowing communications with other Shark devices in the same AWS region instead of being limited to its own device. This overly permissive cloud policy enables a certificate obtained from one vacuum to connect with numerous others.

      Shark RV2320S Shark

      If exploited, an attacker could remotely send commands to at-risk vacuums, access live camera feeds, download homeowners' maps, extract Wi-Fi passwords apparently stored in plaintext, and potentially establish a foothold on the victim’s local network. The researcher detected over 1.5 million unique Shark devices in a single AWS region within 24 hours, with approximately 673,000 devices responding in a way that hinted at support for remote command execution. While this does not confirm that all those devices are vulnerable, it suggests that a significant number of products could be affected.

      However, the attack is not as straightforward as someone hacking a vacuum via the internet. Initially, an attacker needs physical access to a compatible Shark vacuum to retrieve its embedded certificate through a debugging interface. This drastically increases the difficulty, making the attack more likely to be executed by skilled researchers or determined attackers rather than casual hackers.

      The downside is that once such a certificate is obtained, the subsequent steps of the attack can be conducted remotely using SharkNinja’s cloud infrastructure. The researcher pointed out that the fundamental issue lies in the company's cloud-side AWS IoT policy, meaning users cannot resolve it by performing a firmware update. The mitigation measures must be applied by SharkNinja on its servers.

      What should Shark owners do?

      The researcher mentioned that the vulnerability was first communicated to SharkNinja in March 2026, but there was no patch available at the time of publication. Reports have indicated that a CVE identifier has not been assigned to this issue, and SharkNinja has not yet publicly released a fix.

      Until the company resolves the situation, users who do not utilize smart features may want to disconnect their robot vacuum from Wi-Fi or disable remote functionalities to minimize the attack scope. While this serves as a temporary workaround rather than a definitive solution, the ultimate responsibility rests with the manufacturer due to the nature of this cloud-side vulnerability.

A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home. A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home. A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home. A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home. A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home. A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home. A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home.

Other articles

The latest handheld from ONEXPLAYER features the AMD Ryzen AI Max+ 388 and liquid cooling, priced quite steeply. The latest handheld from ONEXPLAYER features the AMD Ryzen AI Max+ 388 and liquid cooling, priced quite steeply. ONEXPLAYER has begun selling the X2 Mini Pro directly, featuring up to 64GB of RAM, an AMD Ryzen AI Max+ 388 processor, optional liquid cooling, with prices going up to $3,229. The Galaxy Watch Ultra 2 is set to take the plunge, and the Watch 9 40mm is equipped with a larger battery. The Galaxy Watch Ultra 2 is set to take the plunge, and the Watch 9 40mm is equipped with a larger battery. A new leak regarding the Galaxy Watch clarifies a previous assertion about the battery and indicates that the Galaxy Watch Ultra 2 might finally be appropriate for freediving and scuba diving. Call of Duty: NEXT has returned, and it will launch the beta for Modern Warfare 4. Call of Duty: NEXT has returned, and it will launch the beta for Modern Warfare 4. Activision has announced that Call of Duty: NEXT will be back on August 21, launching the beta for Modern Warfare 4 along with new multiplayer gameplay, announcements, and insights from developers. New YouTube guidelines aim to eliminate poorly made AI content and clickbait tactics. New YouTube guidelines aim to eliminate poorly made AI content and clickbait tactics. In a significant step to safeguard viewer engagement and advertiser investments, YouTube has revised its monetization policies to cut off revenue from subpar, AI-generated content. The streaming powerhouse is adjusting the regulations surrounding its profitable YouTube Partner Program (YPP) to specifically address “inauthentic content” that is created solely for low-effort content farming. Instead of prohibiting artificial intelligence […] Beatbot AquaSense X review: The pool cleaner for those seeking a luxurious experience. Beatbot AquaSense X review: The pool cleaner for those seeking a luxurious experience. Equipped with a self-cleaning dock and AI navigation, the Beatbot AquaSense X is the pinnacle of luxury in pool cleaning, provided you're willing to spend significantly for that convenience. Chery's newest electric vehicle features top-tier technology at the cost of a basic Tesla, but it's not available for purchase. Chery's newest electric vehicle features top-tier technology at the cost of a basic Tesla, but it's not available for purchase. Chery's Exeed has introduced the 2027 Exlantix ES, featuring a Falcon 700 driving system powered by Nvidia hardware, along with EREV and BEV options, and a starting price of approximately $26,500.

A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home.

A recently revealed vulnerability in SharkNinja devices may allow attackers to gain access to robot vacuum cameras, home mapping data, and Wi-Fi passwords due to an unaddressed cloud security issue that impacts millions of units.