Wyze Cameras Allow Accidental User Spying

This isn't the first time that Wyze, a Seattle-based company offering smart home products such as cameras and doorbells, has experienced a cybersecurity issue like this.
In September 2023, Wyze camera users reported that they were seeing camera feeds that were not theirs.
According to Wyze, this issue was the result of a Web caching problem.
Now this issue is occurring once again, but at a seemingly greater scale.
Around 13,000 users received thumbnails from cameras that were not theirs, and 1,504 of those users enlarged the image.
There were also instances where the thumbnail was attached to a video and the video was viewed.
The User Point of View At least 10 individuals on Reddit reported that they were seeing images on the Wyze app that did not belong to their household.
For one person, the picture was of a stranger's porch.
For another, it was someone else's living room.
Some were seeing footage from a different time zone altogether.
Users were seeing these thumbnails for cameras that weren't their own in the Wyze app's Events tab, according to David Crosby, Wyze co-founder and chief marketing officer.
Once reports of the privacy issue began to come in, the Events tab was taken down.
A new, extra layer of verification has now been added, Crosby noted, and all users must log out of the Wyze app and reset tokens if they have been active.
AWS did not report an outage during the time the Wyze cameras were facing these issues.
An investigation is still underway, and though Wyze has seemingly been much more transparent during this cyber incident compared with the last, it's unclear how this will affect user trust, or how the company will prevent something like this from happening again.


This Cyber News was published on www.darkreading.com. Publication date: Tue, 20 Feb 2024 22:15:10 +0000


Cyber News related to Wyze Cameras Allow Accidental User Spying

RCE exploit for Wyze Cam v3 publicly released, patch now - A security researcher has published a proof-of-concept exploit for Wyze Cam v3 devices that opens a reverse shell and allows the takeover of vulnerable devices. Wyze Cam v3 is a top-selling, inexpensive indoor/outdoor security camera with support for ...
1 year ago Bleepingcomputer.com
Wyze Cameras Allow Accidental User Spying - This isn't the first time that Wyze, a Seattle-based company offering smart home products such as cameras and doorbells, has experienced a cybersecurity issue like this. In September 2023, Wyze camera users reported that they were seeing camera feeds ...
1 year ago Darkreading.com
Home Security Cameras: Keeping an Eye on Your World - As technology advances, home security cameras have become a popular option for households seeking to increase their protection. This article will explore the various types of home security cameras available, the advantages they provide, and factors ...
1 year ago Securityzap.com Meow
How to protect IP surveillance cameras from Wi-Fi jamming - Gone are the days of criminals cutting camera wires to evade detection: with the proliferation of affordable internet-connected cameras, burglars must resort to Wi-Fi jamming. Blocking the signal blinds the device and stalls home and business ...
1 year ago Helpnetsecurity.com
The Internet Enabled Mass Surveillance. AI Will Enable Mass Spying. - Spying and surveillance are different but related things. If I hired that same private detective to put you under surveillance, I would get a different report: where you went, whom you talked to, what you purchased, what you did. Putting someone ...
1 year ago Schneier.com
Wyze camera glitch gave 13,000 users a peek into other homes - Wyze shared more details on a security incident that impacted thousands of users on Friday and said that at least 13,000 customers could get a peek into other users' homes. The company blames a third-party caching client library recently added to its ...
1 year ago Bleepingcomputer.com
San Francisco Police's Live Surveillance Yields Almost 200 Hours of Spying-Including of Music Festivals - A new report reveals that in just three months, from July 1 to September 30, 2023, the San Francisco Police Department racked up 193 hours and 19 minutes of live access to non-city surveillance cameras. That means for the equivalent of 8 days, police ...
1 year ago Eff.org
Schneier on Security - Spying and surveillance are different but related things. If I hired that same private detective to put you under surveillance, I would get a different report: where you went, whom you talked to, what you purchased, what you did. Putting someone ...
1 year ago Schneier.com
Wyze investigating 'security issue' amid ongoing outage - Wyze Labs is investigating a security issue while experiencing a service outage that has been causing connectivity issues since this morning. In an incident report posted at 6:31 AM PT, the company blamed today's camera and login issues on an AWS ...
1 year ago Bleepingcomputer.com
Due to AI, "We are about to enter the era of mass spying," says Bruce Schneier - In an editorial for Slate published Monday, renowned security researcher Bruce Schneier warned that AI models may enable a new era of mass spying, allowing companies and governments to automate the process of analyzing and summarizing large volumes ...
1 year ago Arstechnica.com
Ukraine says Russia hacked web cameras to spy on targets in Kyiv - Ukraine's security officers said they took down two online surveillance cameras that were allegedly hacked by Russia to spy on air defense forces and critical infrastructure in Ukraine's capital, Kyiv. The cameras were installed on residential ...
1 year ago Therecord.media
CVE-2019-12266 - Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. ...
3 years ago
CVE-2019-9564 - A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze ...
2 years ago
Russia Spies on Kyiv Defenses via Hacked Cameras Before Missile Strike - Russian intelligence hacked online surveillance cameras to spy on air defense activities and critical infrastructure in Kyiv ahead of recent missile strikes, the Security Service of Ukraine has revealed. The Kremlin was able to remotely control two ...
1 year ago Infosecurity-magazine.com
Uncovering Chinas Surveillance of the United States Spies Hackers and Informants - Last week, a Chinese surveillance balloon in the United States caused a diplomatic uproar and raised concerns about how Beijing collects intelligence on its biggest rival. FBI Director Christopher Wray said in 2020 that Chinese spying is the most ...
2 years ago Securityweek.com Silence
Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv - The Security Service of Ukraine has asked owners and operators of webcams in the country to stop broadcasts from their devices over concerns about Russia's intelligence services using the feeds to conduct military reconnaissance against strategic ...
1 year ago Darkreading.com
CVE-2024-6249 - Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is ...
7 months ago Tenable.com
CVE-2024-6247 - Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to ...
7 months ago Tenable.com
CVE-2024-6246 - Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not ...
7 months ago Tenable.com
CVE-2024-6248 - Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not ...
7 months ago Tenable.com
EFF adds surveillance hub so Americans can check spying The Register - For a country that prides itself on being free, America does seem to have an awful lot of spying going on, as the new Street Surveillance Hub from the Electronic Frontier Foundation shows. The Hub contains detailed breakdowns of the type of ...
1 year ago Go.theregister.com Meow
How are the AI-powered Robocop Keeping New York's Busiest Subway Station Safe? - Sharing her experience with the AI-powered robot cop in a New York subway station, ZDNET's Nina Raemont reported of the robot - K5 - patrolling in The Times Square-42nd St. subway station's mostly deserted mezzanine. It was pacing swiftly from one ...
1 year ago Cysecurity.news
CVE-2019-11560 - A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras ...
3 years ago
Hackers Can Access Dahua Security Cameras Through Vulnerabilities - Researchers have uncovered a security flaw that could be used by remote hackers to alter the timestamp of videos recorded by Dahua security cameras. This vulnerability, known as CVE-2022-30564, was discovered last year by Redinent Innovations, an ...
2 years ago Securityweek.com CVE-2022-30564
Microsoft Cloud Users Store Personal Data In Europe - In effort to resolve privacy worries, Microsoft is to allow its cloud customers to store all personal data within EU. Microsoft has confirmed that it will allow cloud customers to store all their personal data within the European Union, in an effort ...
1 year ago Silicon.co.uk