A vulnerability in the Shark vacuum that hasn't been fixed may jeopardize your smart home security.
The vulnerability impacts SharkNinja robot vacuums and arises from a misconfigured cloud security policy instead of a firmware issue.
Robot vacuums are designed to clean homes, but it appears this model was mapping them for outsiders. Security researchers have revealed a significant vulnerability in SharkNinja's cloud-connected robot vacuums that might enable attackers to remotely access sensitive data, such as live camera feeds, home layouts, Wi-Fi passwords, and even send commands to the affected devices. Alarmingly, this issue has reportedly not been patched even though it was responsibly reported to SharkNinja months ago.
How can a vacuum become a spy?
The flaw was identified by security researcher tokay0, who reverse-engineered a Shark RV2320EDUS robot vacuum. The research indicates that the device has an AWS IoT certificate that permits communication with other Shark devices within the same AWS region, rather than being limited to its own unit. This overly permissive cloud policy essentially allows a certificate extracted from one vacuum to connect with multiple others.
Should this vulnerability be exploited, an attacker could remotely send commands to affected vacuums, access camera feeds, download maps of the user's residence, retrieve Wi-Fi passwords allegedly stored as plaintext, and potentially establish a foothold on the victim's local network. The researcher detected over 1.5 million unique Shark devices in a single AWS region within 24 hours, with around 673,000 devices responding in a way that indicated they could support remote command execution. While this doesn't confirm that each of those devices is vulnerable, it suggests that a significant number may be affected.
However, it's important to note that the attack is not as straightforward as simply hacking a vacuum over the internet. An attacker must first gain physical access to a compatible Shark vacuum to extract its embedded certificate through a debug interface. This significantly heightens the entry barrier, making it more likely that the attack would be executed by skilled researchers or determined attackers rather than casual hackers.
The downside is that once such a certificate has been obtained, the subsequent actions can occur remotely via SharkNinja's cloud infrastructure. The researcher points out that the core issue lies in the company's cloud-side AWS IoT policy, meaning users cannot rectify it on their own with a firmware update. The necessary fix needs to be applied by SharkNinja on its servers.
What should Shark owners do?
The researcher indicates that the vulnerability was initially reported to SharkNinja in March 2026, but no patch had been made available at the time of publication. Additionally, reports highlight that there is currently no CVE identifier assigned to the issue, and SharkNinja has not yet made a public announcement regarding a solution.
Until the company resolves the issue, users who do not utilize smart features may want to consider disconnecting their robot vacuum from Wi-Fi or disabling remote functionalities to minimize the risk. This is a temporary solution rather than a true fix, but since it is a cloud-side vulnerability, the onus ultimately lies with the manufacturer.
Other articles
A vulnerability in the Shark vacuum that hasn't been fixed may jeopardize your smart home security.
A recently revealed vulnerability in SharkNinja may allow attackers to gain access to robot vacuum cameras, home layouts, and Wi-Fi passwords due to an unaddressed cloud security issue impacting millions of devices.
