Skip to main content
  1. Home
  2. Smart Home
  3. News

An unpatched Shark vacuum flaw could put your smart home at risk

The vulnerability affects SharkNinja robot vacuums and stems from a misconfigured cloud security policy rather than a firmware bug.

Add as a preferred source on Google
Shark RV2320S Matrix Self-Emptying Robot Vacuum Featured
Shark

Robot vacuums are supposed to clean the house. Turns out this one was mapping it for strangers. Security researchers have disclosed a critical vulnerability affecting SharkNinja’s cloud-connected robot vacuums that could allow attackers to remotely access sensitive information, including live camera feeds, home maps, Wi-Fi passwords, and even execute commands on affected devices. More concerningly, the issue reportedly remains unpatched despite being responsibly disclosed to SharkNinja months ago.

How can a vacuum become a spy?

The flaw was discovered by security researcher tokay0, who reverse-engineered a Shark RV2320EDUS robot vacuum. According to the research, the device contains an AWS IoT certificate that is allowed to communicate with other Shark devices in the same AWS region, rather than being restricted to its own device. That overly broad cloud policy effectively allows a certificate extracted from one vacuum to interact with many others.

If exploited, an attacker could remotely issue commands to vulnerable vacuums, access camera feeds, download maps of a user’s home, retrieve Wi-Fi passwords reportedly stored in plaintext, and potentially gain a foothold on the victim’s local network. The researcher observed more than 1.5 million unique Shark devices in a single AWS region over 24 hours, with around 673,000 devices responding in a way that suggested support for remote command execution. While that doesn’t confirm every one of those devices is exploitable, it indicates the issue could affect a very large number of products.

Recommended Videos

To be fair, the attack isn’t as simple as someone hacking a vacuum over the internet. To begin with, an attacker first needs physical access to a compatible Shark vacuum in order to extract its embedded certificate through a debug interface. That significantly raises the barrier to entry, making the attack more likely to be carried out by skilled researchers or determined attackers rather than opportunistic hackers.

The bad news is that once such a certificate has been extracted, the rest of the attack can take place remotely through SharkNinja’s cloud infrastructure. According to the researcher, the underlying problem lies in the company’s cloud-side AWS IoT policy, meaning users can’t fix it themselves with a firmware update. The required mitigation has to be implemented by SharkNinja on its servers.

What should Shark owners do?

The researcher says the vulnerability was first disclosed to SharkNinja in March 2026, but no patch had been released at the time of publication. Reports also note that there is currently no CVE identifier assigned for the issue, and SharkNinja has yet to publicly announce a fix.

Until the company addresses the problem, users who don’t rely on smart features may want to consider disconnecting their robot vacuum from Wi-Fi or disabling remote functionality to reduce the attack surface. It’s a temporary workaround rather than a true fix, but since this is a cloud-side vulnerability, the responsibility ultimately lies with the manufacturer.

Varun Mirchandani
Varun is an experienced technology journalist and editor with over eight years in consumer tech media. His work spans…
Beatbot AquaSense X review: The pool cleaner for those that want to be pampered
It's a nothing short of a self-cleaning nirvana for your pool. But as they say, nothing fine comes without a fittingly handsome fee.
Beatbot Aquasense X robot, AstroRinse station and iSkim

view at amazon

Quick take: 

Read more
Google Home Speaker (2026) review: Smarter and punchier, with a subscription pinch
Google's latest smart speaker pairs Gemini with better sound and deeper smart home integration. What's not to love without spending over a $100?
Sphere, Body Part, Finger

View at Amazon

Quick Recap

Read more
I tried to parody the most absurd AI products, but the tech industry beat me to it
The joke was supposed to be that every household object gets cameras, AI insights, and a premium tier. Apparently, that’s now a business plan
Imaginary AI products

I wanted to invent an AI product so silly that no founder could turn it into a seed round.

It had to solve a problem nobody had, collect far more data than the problem deserved, and turn normal behavior into an insight that sounded vaguely disappointed in its owner. Somewhere around the third feature, it would ask for a subscription.

Read more