Unpatched SharkNinja flaw turns vacuum cleaner into a spy, reveals house maps, WiFi passwords
Is your Shark vacuum robot spying on you?

Image by Cybernews.
- Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.
- Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.
- The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.
- Attackers need physical device access first, limiting the risk mainly to technically skilled people with a Shark device.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A design flaw in the Shark vacuum cleaner allows attackers to turn your vacuum robot into a spy with camera access and home plans. The researcher behind the discovery claims the company failed to solve the problem after over three months, leaving the issue unpatched.
The Shark security flaw, discovered in March 2026, allows attackers to remotely access vacuums and watch surroundings via the device’s camera. If that’s not bad enough, the security researcher behind the discovery, Tokay0, says attackers can access users’ WiFi passwords and even copy the layout of the house.
“Millions of Shark vacuums are currently vulnerable to remote code execution. This critical vulnerability leaves hackable cameras with wheels inside the homes of Shark vacuum owners,” Tokay0’s blog reads.
The problem lies with an unpatched AWS Internet of Things (IoT) policy flaw within the Shark vacuums. The researcher discovered the problem after disassembling a Shark RV2320EDUS robot vacuum. The device is made by SharkNinja, a major US technology company with revenues exceeding $6.3 billion.
We have reached out to the company for comment and will update this article once we receive a reply.
Meanwhile, according to Tokay0, the device contained an embedded AWS IoT certificate that enabled it to connect to Shark devices in the same AWS region. The key technical problem lies within the devices’ Message Queuing Telemetry Transport (MQTT), which allows a stolen certificate from one device to access another in the same AWS Cloud region.
AWS Cloud operates via 39 completely isolated geographic regions. So, for example, a vulnerable Shark device would allow an attacker to connect to other devices in AWS US West (Northern California) region, but not AWS Europe (London) region.
However, the researcher believes that a vast number of SharkNinja devices are exposed. According to the blog entry, 673,000 SharkNinja devices were observed to be exposed over a 24-hour period in the same AWS region where the researcher resides.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
At the same time, over 1.5 million unique SharkNinja devices were observed in the same AWS region. If a similar proportion of affected devices existed across all 39 AWS Cloud regions, the number of exposed devices could reach into the millions.
“A very large number of SharkNinja IoT devices are affected by this vulnerability. Although devices can only authenticate to the region that their certificates are bound to due to regional certificate pinning, it would be trivial for an attacker to purchase devices tied to specific regions to gain control of devices in that region,” the researcher explained.
While the research focused mainly on RV2320EDUS and AV1102ARUS, other Shark vacuum robots may also be exposed to the vulnerability. Last year, SharkNinja sold over 28 million units worldwide.
According to Tokay0, the vulnerability remains unpatched. The researcher claims they disclosed the issue to SharkNinja, but the company responded with a lackluster response.
“SharkNinja basically responded with a vague 'we are working on it.’ After several attempts to reach out and ask for more details with no response, I gave up,” the researcher explained in a blog post.
The blog, detailing the issue, was posted 90 days after the initial disclosure, Tokay0 claims.
The only silver lining is that for the robot-vacuum security flaw to work, attackers first need to physically disassemble the device and steal the certificate, which makes the attack path accessible to mostly technically savvy individuals.
Based in Needham, Massachusetts, SharkNinja is a major product design and tech company. The company sells robotic vacuums, air purification systems, kitchen appliances, and many other devices for home use.