Skip to main content
  1. Home
  2. Audio / Video
  3. News

A major Sonos exploit was explained at Black Hat — but you needn’t worry

Add as a preferred source on Google
A Sonos One speaker sitting on an outdoor table.
This aging Sonos One looks like it's seen a thing or two — but it's also continued to see security updates. Phil Nickinson / Digital Trends

Hardware exploits, in a very oversimplified sense, can be broken down into two categories: Those you should care about, and those you shouldn’t. And this one firmly sits in the category of exploits that you really need not lose sleep over. But given that it involves Sonos — and because Sonos has rightly been the subject of less-than-positive headlines of late — it’s at least worth discussing.

So here’s the deal: A presentation by NCC Group’s Robert Herrera and Alex Plaskett at the August Black Hat USA 2024 conference in Las Vegas showed how a Sonos One could be exploited to allow an attacker to capture audio in real time off the device, thanks to a kernel vulnerability initiated by a flaw in the Wi-Fi stack. That, obviously, is not good. The Sonos One was the first speaker from the company to use a microphone to allow for hands-free voice control.

Recommended Videos

When the Sonos One connects to a router, there’s a handshake that happens before you can send wireless traffic, Herrera explained in an interview with Dark Reading. One of the packets exchanged was not properly validated, and that vulnerability is how an attacker could force their way into the device, and from there access the microphones.

“We deploy a method of capturing all the audio data — all the microphone input in the room, in the vicinity of this Sonos device,” Plaskett told Dark Reading ahead of his and Herrera’s presentation. An attacker is then “able to exfiltrate that data and play it back at a later date, and be able to play back all the recorded conversations from the room.”

It’s a real-time thing, though. The attacker couldn’t hear what was said before the exploit was leveraged. “You would need to exploit the Sonos device first to start the capture,” Plasket said. “And then once you start the capture, you only … have the data from within that period.”

But the proof of concept shown was not easy to implement and not the sort of thing you’d be able to do without actually being nearby someone’s Sonos One. (Other devices could be at risk, Plaskett and Herrera said, but that was more a function of the Wi-Fi flaw.)

“If an attacker goes to that kind of extent, they could compromise the devices,” Plaskett said. “And I think people have been assuming that these devices may be secure. So being able to kind of quantify the amount of effort and what an attacker would need to actually achieve the compromise is quite an important understanding.”

Perhaps most important is that the exploit was fixed within a couple months of being reported, with an update to the Sonos S2 system coming in October 2023, and an S1 update about a month later. Sonos publicly acknowledged the remote code execution vulnerability in a bulletin — again, nearly a year after actually patching its own devices — on August 1, 2024. MediaTek — whose Wi-Fi stack was the root problem here — issued its own security advisory in March 2024.

“The security posture of Sonos devices is a good standard. It’s been evolving over time,” Plaskett said. “Every vendor has vulnerabilities, and basically, it’s about how you respond to those vulnerabilities. How you patch those vulnerabilities. Sonos fixed these vulnerabilities within two months. … Yeah, it’s a good patching process, I would say.”

Phil Nickinson
Former Section Editor, Audio/Video
Phil spent the 2000s making newspapers with the Pensacola (Fla.) News Journal, the 2010s with Android Central and then the…
Amazon is adding Alexa Plus to Fire TV devices without charging extra
Fire TV users can now search by describing what they want, ask follow-up questions, and control smart home devices with Alexa Plus.
Computer Hardware, Electronics, Hardware

If you use a Fire TV, Amazon just gave it a pretty substantial AI upgrade. Alexa+ is now rolling out at no extra cost to compatible Fire TV devices across the U.S., including current-generation Fire TV Sticks, the Fire TV Cube, Amazon Ember TVs, and supported sets from brands like Hisense and Panasonic.

There is no subscription to activate, no app to download, and you do not need a Prime membership. Eligible devices are upgraded automatically.

Read more
Sony’s $220 PlayStation speakers pack one feature I wish every desktop setup had
PlayStation finally made gaming speakers, and they do much more than blast game audio
Sony PlayStation Pulse Elevate Speakers

Sony showcased its first PlayStation wireless speakers almost a year ago alongside the release date reveal for Wolverine, and now we finally know when gamers get to put them on their desks. The Pulse Elevate wireless speakers launch on November 12, Sony announced in an August 18 update to its original reveal. Preorders begin September 1 at 10 am local time, or 10 am ET in the US.

Midnight Black will be sold globally through PlayStation Direct and participating retailers, while the White edition will have more limited availability. Priced at $219.99, the company is bringing a surprising amount of the technology from its Pulse gaming headset line out of your ears and onto your setup.

Read more
Spotify’s Playlist Notes makes it easier to add context to your favorite picks
Ever wonder why a song landed on your favorite playlist? Now you can just ask, or answer it yourself.
Spotify notes feature

If you have ever wondered why a specific song made its way to a playlist, Spotify’s new Playlist Notes feature is here to help. The feature lets editors and users add context to their songs, podcasts, and audiobook picks. 

The feature joins the long line of playlist improvements, including custom cover art, the ability to organize playlists into folders, and smooth transitions between tracks, that make it easier to personalize your listening experience and make your playlists feel more like your own.

Read more