Most Viewed Content:

OpenAI Launched Assistants API, Allowing Developers to Customize AI Assistants with One Click

At today's OpenAI's first developer conference, OpenAI launched the...

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

Apple will not produce 27-inch iMac equipped with a Silicon processor

The Verge reported tonight that Apple will no longer...

Google awards $107,500 bounty for security expert reporting critical Google Home bug

Security research expert Matt Kunze reported a serious vulnerability of Google Home to Google last year, and recently won a high bounty of US$107,500 (about 749,000 CNY) from Google.

A vulnerability has been found on the Google Home smart audio device, which allows attackers to install a backdoor account for remote control and activate the microphone for listening to user conversations. Kunz disclosed all the technical details of the vulnerability and how it could be exploited earlier this week.

Kunz scanned through Nmap and found the port of Google Home’s local HTTP API. So he set up a proxy to capture encrypted HTTPS traffic, hoping to hijack user authorization tokens.

The researchers discovered that adding a new user to a targeted device is a two-step process that requires the device name, a certificate, and a “cloud ID” from its local API. With this information, they can send a link request to a Google server.

Even more worryingly, the researchers found a way to abuse the “call [phone number]” command, adding it to a malicious routine that would activate a microphone at a specified time, call the attacker’s number and Send a live microphone feed.

Kunz discovered the issues in January 2021 and sent more details and a PoC in March 2021. Google fixed everything in April 2021.

Latest

Mercedes-Benz to Unveil New E-Class Standard-Axis Sports Version at Beijing Auto Show

Recently, we learned from Mercedes-Benz officials that the new...

Changan Mazda releases fourth preview image of new model

Changan Mazda released the fourth preview image of its...

Huawei Pura 70 Ultra satellite messaging supports sending pictures

Bruce Lee, CTO of Huawei Terminal BG, demonstrated the...

Google Pixel 9 Pro real phone images exposed: Tensor G4 chip, 16GB memory

The source rozetked recently published a blog post and...

Newsletter

Don't miss

Mercedes-Benz to Unveil New E-Class Standard-Axis Sports Version at Beijing Auto Show

Recently, we learned from Mercedes-Benz officials that the new...

Changan Mazda releases fourth preview image of new model

Changan Mazda released the fourth preview image of its...

Huawei Pura 70 Ultra satellite messaging supports sending pictures

Bruce Lee, CTO of Huawei Terminal BG, demonstrated the...

Google Pixel 9 Pro real phone images exposed: Tensor G4 chip, 16GB memory

The source rozetked recently published a blog post and...

Google Pixel 8a high-definition renderings exposed again

Android Headline published a blog post today, sharing more...
Threza Gabriel
Threza Gabrielhttps://www.techgoing.com
Threza Gabriel is a news writer at TechGoing. TechGoing is a global tech media to brings you the latest technology stories, including smartphones, electric vehicles, smart home devices, gaming, wearable gadgets, and all tech trending.

Mark Gurman Predicts Apple’s M4 Mac Series Release Roadmap for Late 2024

Bloomberg’s Mark Gurman recently revealed that Apple is accelerating the development of the M4 series of Apple Silicon chips, which are expected to be...

Audi RS e-tron GT Performance preview image revealed

Recently, Audi officially released a set of preview images of the RS e-tron GT Performance. As the flagship model in the Audi e-tron GT...

Spy Photos of the Next-Gen BMW X3 Exposed, H1 Release Expected

Recently, BMW officially released test spy photos of the new generation X3 (G45). It is reported that the new car may make its debut...