Wyze was aware of a major camera security flaw for three years
in March 2019, but that the device maker didn't inform customers, recall the product or fully patch the problem in the three years since. In fact, Wyze couldn't completely fix the issue — while it did mitigate the problem with patches, it's now clear the companyThe vulnerability let attackers remotely control the camera without knowing the value normally needed to authenticate.
Wyze was slow to respond and didn't fully share the nature of the security hole. Bitdefender noted that Wyze only acknowledged reception of the warning in November 2020, a year and a half after it was delivered. And while it did tell customers that it discontinued the Wyze Cam v1 due to incompatibility with a security update, it didn't tell users this was a known three-year-old flaw.
It's not clear if any hackers took advantage of the flaw, but the potential consequences were serious. An intruder could have looked at past activity in the home or disabled the camera ahead of a burglary. There are also questions surrounding Bitdefender's very late disclosure. The company's PR director Steve Fiore toldthat it delays publishing reports when it's not clear a vendor can properly address an issue. It didn't want to expose"potentially millions" of Wyze Cam users by sharing details of the exploit to with the public.
All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Canada Latest News, Canada Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
I’m done with WyzeWhy are we only hearing about a huge security flaw now?
Read more »
I’m done with WyzeWhy are we only hearing about a huge security flaw now?
Read more »
GoPro's Volta battery grip addresses its cameras' biggest weakness | EngadgetThe company has also launched a Hero 10 Black Creator Edition package..
Read more »
'Possible Coverup': White House Logs Show 7-Hour Gap in Trump's Calls on Jan. 6NEW: Former National Security Adviser John Bolton said on Tuesday that Trump used the term “burner phones” and was aware of its meaning, according to a new report.
Read more »
Axie Infinity's Ronin Sidechain Suffers $625 Million HackThe Ronin bridge has been drained of more than $600 million in what appears to be the biggest DeFi hack in history
Read more »