Unpatched SharkNinja flaw turns vacuum cleaner into a spy, researcher claims
Is your Shark vacuum robot spying on you?

Image by Cybernews.
- Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.
- Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.
- The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.
- Attackers need physical device access first, limiting the risk mainly to technically skilled people with a Shark device.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A design flaw in the Shark vacuum cleaner allows attackers to turn your vacuum robot into a spy with camera access and home plans. The researcher behind the discovery claims the company failed to solve the problem after over three months, leaving the issue unpatched. Meanwhile, SharkNinja says the company addressed the vulnerability.
The Shark security flaw, discovered in March 2026, allows attackers to remotely access vacuums and watch surroundings via the device’s camera. If that’s not bad enough, the security researcher behind the discovery, Tokay0, says attackers can access users’ WiFi passwords and even copy the layout of the house.
“Millions of Shark vacuums are currently vulnerable to remote code execution. This critical vulnerability leaves hackable cameras with wheels inside the homes of Shark vacuum owners,” Tokay0’s blog reads.
The problem lies with an unpatched AWS Internet of Things (IoT) policy flaw within the Shark vacuums. The researcher discovered the problem after disassembling a Shark RV2320EDUS robot vacuum. The device is made by SharkNinja, a major US technology company with revenues exceeding $6.3 billion.
Meanwhile, SharkNinja said the company is aware about the researcher's report and has “addressed” the issue.
“SharkNinja is aware of the researcher’s report on some of our robot vacuums, and we have completely addressed the identified vulnerability. We take privacy and data security incredibly seriously, and we remain committed to protecting the privacy and data security of our consumers,” the company said.
How many devices may have been affected?
According to Tokay0, the device contained an embedded AWS IoT certificate that enabled it to connect to Shark devices in the same AWS region. The key technical problem lies within the devices’ Message Queuing Telemetry Transport (MQTT), which allows a stolen certificate from one device to access another in the same AWS Cloud region.
AWS Cloud operates via 39 completely isolated geographic regions. So, for example, a vulnerable Shark device would allow an attacker to connect to other devices in AWS US West (Northern California) region, but not AWS Europe (London) region.
However, the researcher believes that a vast number of SharkNinja devices are exposed. According to the blog entry, 673,000 SharkNinja devices were observed to be exposed over a 24-hour period in the same AWS region where the researcher resides.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
At the same time, over 1.5 million unique SharkNinja devices were observed in the same AWS region. If a similar proportion of affected devices existed across all 39 AWS Cloud regions, the number of exposed devices could reach into the millions.
“A very large number of SharkNinja IoT devices are affected by this vulnerability. Although devices can only authenticate to the region that their certificates are bound to due to regional certificate pinning, it would be trivial for an attacker to purchase devices tied to specific regions to gain control of devices in that region,” the researcher explained.
While the research focused mainly on RV2320EDUS and AV1102ARUS, other Shark vacuum robots may also be exposed to the vulnerability. Last year, SharkNinja sold over 28 million units worldwide.
The researcher claims they disclosed the issue to SharkNinja, but the company responded with a lackluster response.
Have thoughts about this topic? Others do, too. Join them in the discussion.
“SharkNinja basically responded with a vague 'we are working on it.’ After several attempts to reach out and ask for more details with no response, I gave up,” the researcher explained in a blog post.
The blog, detailing the issue, was posted 90 days after the initial disclosure, Tokay0 claims.
The only silver lining is that for the robot-vacuum security flaw to work, attackers first need to physically disassemble the device and steal the certificate, which makes the attack path accessible to mostly technically savvy individuals.
Based in Needham, Massachusetts, SharkNinja is a major product design and tech company. The company sells robotic vacuums, air purification systems, kitchen appliances, and many other devices for home use.
Updated on July 21st [07:15 a.m. GMT] with a statement from SharkNinja.