IoT Security

Vulnerability Allowed Eavesdropping via Sonos Smart Speakers

Sonos has patched vulnerabilities in its smart speakers, including a serious flaw that could have been exploited to eavesdrop on users.

Sonos has patched vulnerabilities in its smart speakers, including a serious flaw that could have been exploited to eavesdrop on users.

LAS VEGAS — BLACK HAT USA 2024 — NCC Group researchers have disclosed vulnerabilities found in Sonos smart speakers, including a flaw that could have been exploited to eavesdrop on users.

One of the vulnerabilities, tracked as CVE-2023-50809, can be exploited by an attacker who is in Wi-Fi range of the targeted Sonos smart speaker for remote code execution. 

The researchers demonstrated how an attacker targeting a Sonos One speaker could have used this vulnerability to take control of the device, covertly record audio, and then exfiltrate it to the attacker’s server.

Sonos informed customers about the vulnerability in an advisory published on August 1, but the actual patches were released last year. MediaTek, whose Wi-Fi SoC is used by the Sonos speaker, also released fixes, in March 2024. 

According to Sonos, the vulnerability affected a wireless driver that failed to “properly validate an information element while negotiating a WPA2 four-way handshake”.

“A low-privileged, close-proximity attacker could exploit this vulnerability to remotely execute arbitrary code,” the vendor said.

Advertisement. Scroll to continue reading.

In addition, the NCC researchers discovered flaws in the Sonos Era-100 secure boot implementation. By chaining them with a previously known privilege escalation flaw, the researchers were able to achieve persistent code execution with elevated privileges.

NCC Group has made available a whitepaper with technical details and a video showing its eavesdropping exploit in action.

Related: Internet-Connected Sonos Speakers Leak User Information 

Related: Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023

Related: New ‘LidarPhone’ Attack Uses Robot Vacuum Cleaners for Eavesdropping

Related Content

Endpoint Security

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.

Vulnerabilities

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.

Artificial Intelligence

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.

Artificial Intelligence

An attacker could self-register, sign in for board-level API access, and import a new company for code execution.

Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.

Vulnerabilities

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.

Mobile & Wireless

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version