#10
The Hacker News
general
August 28, 2026 at 12:07 UTC
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
By [email protected] (The Hacker News)
AI Summary
Researcher Olivier Laflamme disclosed two root RCE chains in the Unitree G1 EDU humanoid robot, tracked as CVE-2026-76639 and CVE-2026-76640, with one exploit path reachable via Bluetooth Low Energy targeting the robot's Locomotion PC through chat_go and bashrunner components. Physical-adjacent attackers could gain full root control of the robot without network access, posing serious safety implications for research and industrial environments deploying humanoid robotics. These findings underscore the expanding attack surface of AI-integrated physical systems.
Relevance score: 62.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →