Skip to main content
  1. Home
  2. Smart Home
  3. Computing
  4. News

Fix upcoming for Google Home, Chromecast bug that can tattle on your location

Add as a preferred source on Google
GoogleFindMyHomeDemo

Your trusty Google Home speaker may not be all that trustworthy after all — at least, not for now. Security researcher Craig Young from the firm Tripwire has discovered a bug that allows both the Google Home and the Google Chromecast TV stick to share user location, which needless to say is less than ideal. Apparently, the bug works by exploiting a loophole, and results in cross-checking the wireless networks in the vicinity with Google’s exacting geolocation services.

Recommended Videos

But don’t worry — this vulnerability won’t be present for long. On Monday, June 18, security expert Brian Krebs reported that Google will fix the location privacy leak “in the coming weeks.” And not a moment too soon — exploiting the bug is apparently quite straightforward, and requires attackers to simply run a script in the background in order to collect location data on anyone with a Google Home or Chromecast installed on their local network. The attacker wouldn’t even need to be connected to your network; they would only need to send you a malicious link, and for you to keep that link open for about a minute while they triangulated your position.

“I’ve only tested this in three environments so far, but in each case the location corresponds to the right street address,” Young told Krebs. “The Wi-Fi based geolocation works by triangulating a position based on signal strengths to Wi-Fi access points with known locations based on reporting from people’s phones.” Although IP-based geolocation is only accurate to about three miles around the compromised device, the method that Young has discovered actually delivers location data to an accuracy of about 30 feet. Young has even produced a demo of the bug in action, which you can check out in the above video.

Krebs notes that Google only agreed to address the issue after he contacted them and informed the team that he would be publishing a piece about the problem. In fact, Young had previously made contact with Google, but the tech giant refused to issue a patch, noting that the geolocation feature was “intended behavior.” Clearly, Google has changed its tune, and now, the fix should go live in mid-July.

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Beatbot AquaSense X review: The pool cleaner for those that want to be pampered
It's a nothing short of a self-cleaning nirvana for your pool. But as they say, nothing fine comes without a fittingly handsome fee.
Beatbot Aquasense X robot, AstroRinse station and iSkim

view at amazon

Quick take: 

Read more
An unpatched Shark vacuum flaw could put your smart home at risk
The vulnerability affects SharkNinja robot vacuums and stems from a misconfigured cloud security policy rather than a firmware bug.
Shark RV2320S Matrix Self-Emptying Robot Vacuum Featured

Robot vacuums are supposed to clean the house. Turns out this one was mapping it for strangers. Security researchers have disclosed a critical vulnerability affecting SharkNinja's cloud-connected robot vacuums that could allow attackers to remotely access sensitive information, including live camera feeds, home maps, Wi-Fi passwords, and even execute commands on affected devices. More concerningly, the issue reportedly remains unpatched despite being responsibly disclosed to SharkNinja months ago.

How can a vacuum become a spy?

Read more
Google Home Speaker (2026) review: Smarter and punchier, with a subscription pinch
Google's latest smart speaker pairs Gemini with better sound and deeper smart home integration. What's not to love without spending over a $100?
Sphere, Body Part, Finger

View at Amazon

Quick Recap

Read more