Researchers from Kaspersky, a cybersecurity solutions provider, have uncovered concerning vulnerabilities in a popular smart toy robot, potentially putting children at risk of unauthorized video chats with cybercriminals.
The vulnerabilities, according to Kaspersky, could allow hackers to exploit the toy’s system and communicate with children through video calls without parental consent. This could lead to manipulative interactions where attackers could potentially lure children into unsafe situations.
“When purchasing smart toys, it becomes imperative to prioritize not only their entertainment and educational value but also their safety and security features,” Nikolay Frolov, senior security researcher at Kaspersky’s ICS CERT, said in a media advisory. “Despite the common belief that a higher price tag implies enhanced security, it is essential to understand that even the most expensive smart toys may not be immune to vulnerabilities that attackers can exploit.
READ:
Kaspersky cautions parents of online dangers to school children
Cybercriminals target online games for children as young as 3 — Kaspersky
A robot toy for kids runs on Android and has a camera and microphone. It uses AI to chat with kids by name and change its responses depending on how the child feels. Parents need to install an app on their phone to make the toy work fully. With the app, parents can see how their child is doing with learning activities and call them through the robot.
Security issues on mobile app
During setup, parents are instructed to connect the toy to a Wi-Fi network and link it to their mobile device, providing the child’s name and age. However, Kaspersky researchers found that the API responsible for requesting this information lacks authentication enforcement, potentially enabling cybercriminals to intercept and access sensitive data, including the child’s name, age, and even location.
Security issues in the parent’s mobile application could enable attackers to remotely take control of the toy and gain unauthorized access to the network. By employing brute-force methods to recover the one-time password (OTP) without limits on failed attempts, hackers could link the toy to their account, bypassing parental controls.
To keep all smart devices, secure and protected, Kaspersky experts compiled the following tips:
- Keep your devices updated: Regularly update the firmware and software of all your connected devices, including smart toys. These updates often contain crucial security patches that address known vulnerabilities.
- Research before purchase: Before buying a smart toy or any connected device, research the manufacturer’s reputation for security and privacy. Choose devices from reputable brands that prioritize security and provide regular updates.
- Be cautious with app permissions: Review and limit the permissions granted to mobile apps associated with your smart device. Only provide necessary access to features and data, and avoid granting excessive privileges.
- Power it off when not used: Switch off the smart toy when not in use to prevent data collection. If the device has a microphone, store it in a hard-to-reach place when not active, and cover or redirect any cameras when not in use.
- Use reliable security solutions: Employ a dependable security solution to help secure and protect your entire smart home ecosystem.