< Back to all clusters
[TECHNOLOGY] · China, United States · 4 sources

started · updated

Security Flaws in Kids' Smartwatches Revealed at Black Hat

Security researchers Vangelis Stykas and Felipe Solferini demonstrated that inexpensive GPS‑enabled children’s smartwatches can be hijacked to track a wearer’s location, capture photos, record audio and spoof messages. The devices, sold by the obscure brand CJC and manufactured by YiQingTeng Electronics in Shenzhen, China, lack basic authentication, allowing anyone to access them through the shared backend platform used by dozens of other brands.

During a live test at the Black Hat conference, the researchers used a watch to follow a WIRED reporter through New York, silently taking photos inside an elevator and at a desk, and streaming microphone audio to a remote listener. Their analysis of more than 70 GPS‑enabled watches and car accessories showed that tens of millions of units rely on three major supply‑chain platforms—Wonlex, NewGPS2012 and SinoTrack—each with similar security weaknesses. Server‑side flaws also expose consumer data and could enable unauthorized code execution.

The findings highlight a widespread vulnerability in low‑cost tracking gadgets marketed for children and vehicles, raising concerns about digital stalking and broader privacy risks.

Entities

Black Hat conference · CJC · Felipe Solferini · Vangelis Stykas · YiQingTeng Electronics