Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
7 Articles
7 Articles
Hacker Shows Anyone Near a Unitree G1 Robot Can Seize Root Control
Security researcher Olivier Laflamme disclosed two root remote-code-execution chains in Unitree's G1 EDU humanoid robot, one reachable purely over Bluetooth with no pairing required. Unitree has patched the cloud flaw that let one customer unlock another's robot, but the Bluetooth root path remains a live concern as G1 units spread through university labs worldwide.
A dangerous vulnerability has been discovered in the Unitree robot, which can be used to launch a "machine uprising"
Independent cyber security expert who goes by the pseudonym Boschko Found The Chinese humanoid robot Unitree G1 has two vulnerabilities that allow it to execute code remotely from nearby devices via Bluetooth Low Energy (BLE) without prior pairing and authentication. Image source: unitree.com The research project, called UniBLEed, shows that due to this attack, the […] The post A dangerous vulnerability has been discovered in the Unitree robot, …
Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth
A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals. The flaws could allow a nearby attacker to obtain root-level code execution on the robot’s locomotion computer, which manages […] The post Hackers Can Take Full Control of Unitree G1 Humanoi…
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
Security researcher Olivier Laflamme published an analysis of two attack chains targeting the Unitree G1 humanoid robot. One of them allowed access to the device within Bluetooth range. Unitree's manufacturer confirmed the vulnerabilities and released patches. The robot line...
Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code execution (RCE) from nearby devices via Bluetooth Low Energy (BLE). This research, referred to as UniBLEed, indicates that the attack can compromise the robot’s Locomotion PC, the component responsible for essential functions, without requiring […] This article has been indexed from GBHackers Se…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium










