Skip to main content

A major Sonos exploit was explained at Black Hat — but you needn’t worry

A Sonos One speaker sitting on an outdoor table.
This aging Sonos One looks like it's seen a thing or two — but it's also continued to see security updates. Phil Nickinson / Digital Trends

Hardware exploits, in a very oversimplified sense, can be broken down into two categories: Those you should care about, and those you shouldn’t. And this one firmly sits in the category of exploits that you really need not lose sleep over. But given that it involves Sonos — and because Sonos has rightly been the subject of less-than-positive headlines of late — it’s at least worth discussing.

So here’s the deal: A presentation by NCC Group’s Robert Herrera and Alex Plaskett at the August Black Hat USA 2024 conference in Las Vegas showed how a Sonos One could be exploited to allow an attacker to capture audio in real time off the device, thanks to a kernel vulnerability initiated by a flaw in the Wi-Fi stack. That, obviously, is not good. The Sonos One was the first speaker from the company to use a microphone to allow for hands-free voice control.

Recommended Videos

When the Sonos One connects to a router, there’s a handshake that happens before you can send wireless traffic, Herrera explained in an interview with Dark Reading. One of the packets exchanged was not properly validated, and that vulnerability is how an attacker could force their way into the device, and from there access the microphones.

“We deploy a method of capturing all the audio data — all the microphone input in the room, in the vicinity of this Sonos device,” Plaskett told Dark Reading ahead of his and Herrera’s presentation. An attacker is then “able to exfiltrate that data and play it back at a later date, and be able to play back all the recorded conversations from the room.”

It’s a real-time thing, though. The attacker couldn’t hear what was said before the exploit was leveraged. “You would need to exploit the Sonos device first to start the capture,” Plasket said. “And then once you start the capture, you only … have the data from within that period.”

But the proof of concept shown was not easy to implement and not the sort of thing you’d be able to do without actually being nearby someone’s Sonos One. (Other devices could be at risk, Plaskett and Herrera said, but that was more a function of the Wi-Fi flaw.)

“If an attacker goes to that kind of extent, they could compromise the devices,” Plaskett said. “And I think people have been assuming that these devices may be secure. So being able to kind of quantify the amount of effort and what an attacker would need to actually achieve the compromise is quite an important understanding.”

Perhaps most important is that the exploit was fixed within a couple months of being reported, with an update to the Sonos S2 system coming in October 2023, and an S1 update about a month later. Sonos publicly acknowledged the remote code execution vulnerability in a bulletin — again, nearly a year after actually patching its own devices — on August 1, 2024. MediaTek — whose Wi-Fi stack was the root problem here — issued its own security advisory in March 2024.

“The security posture of Sonos devices is a good standard. It’s been evolving over time,” Plaskett said. “Every vendor has vulnerabilities, and basically, it’s about how you respond to those vulnerabilities. How you patch those vulnerabilities. Sonos fixed these vulnerabilities within two months. … Yeah, it’s a good patching process, I would say.”

Phil Nickinson
Former Section Editor, Audio/Video
Phil spent the 2000s making newspapers with the Pensacola (Fla.) News Journal, the 2010s with Android Central and then the…
Sonos’ public Trello board doesn’t delight
The Sonos app on an iPhone next to a crossword puzzle on an iPad.

At risk of bouncing the rubble even further, we need to talk about where things stand going into September in regards to the state of Sonos. 

For a brief bit of context, Sonos in May updated its app and the underlying system software that controls its family of wireless speakers in preparation for the next generation of products — including the Sonos Ace headphones that arrived just weeks later. That update went poorly, and otherwise working (and not-inexpensive) Sonos systems were left in various stages of disarray. 

Read more
You Asked turns 1, with a major giveaway!
You Asked Feature

Today is the one-year anniversary of You Asked! That's 52 uninterrupted weeks, and it feels like a cool milestone. So let’s take a look back on the year that was, answer some more questions, and give some stuff away!

But first, some numbers! Over the course of the first 51 episodes, we’ve answered over 210 questions. This show has pulled in over 4 million views so far on YouTube, along with over 8,000 comments and 160,000 likes.

Read more
What color Sonos Ace should you get?
Sonos Ace in matte black and matte soft white.

The Sonos Ace headphones in black. Simon Cohen / Digital Trends

A lot of questions remain regarding the new Sonos Ace headphones. Chief among them is how do they sound? Next probably is why don't they really take advantage of all the things the Sonos app does? (Or, maybe, what it currently doesn't do?)

Read more