If you bring technology into your home, you make yourself vulnerable. Because even with systems that are considered comparatively secure, new attack possibilities that enable unauthorized access are constantly being discovered.
This is also the case with the smart speakers from Google. The search engine giant’s devices actually have a pretty good history of security vulnerabilities. Vulnerabilities are mostly caused by weak WiFi passwords or clicking on phishing emails.
Nevertheless, attackers would have had the chance to secure extensive control over Google’s Smart Speaker until 2021, as has now become known.
In his article, Frederic tells you how you can make your own smart home more secure:
Make Smart Home safe
More protection thanks to devices and network
Hackers could have secretly eavesdropped
The vulnerability was discovered by cybersecurity researcher Matt Kunze. In a blog post he revealshow hackers could have remotely taken control of Google’s smart speaker.
A vulnerability in Google’s Cloud API allowed the attackers to gain access to the victim’s Google Home app – and work their way from there to paired devices.
The attacker first created a Google account and then went within range of the victim’s Google Home device. Using the vulnerability, he was now able to connect to the network that the Google devices use during initial setup. From there it was then possible to connect to the victim’s Google account via a Python script.
After the takeover, you would have had extensive access to the victim’s smart home. As examples, he cites secret eavesdropping via a silent call on the device or preparing further attacks, for example to steal the WiFi password.
A video on YouTube shows what such a secret call can look like.
link to YouTube content
The vulnerability has now been fixed
Google was notified of the vulnerability by Kunze in March 2021 after discovering the vulnerability in January. The problem has been fixed by Google since April 2021, so owners of a Google smart speaker with the latest firmware do not have to react themselves.
As a reward for discovering the vulnerability, Google gave Kunze just over $100,000. To his knowledge, the vulnerability was never actually exploited by attackers to gain access to third-party smart homes.
Google’s smart displays, i.e. smart speakers with their own screens, were not affected by the security gap. These require scanning a QR code during setup and protect the setup network with WPA2. An attacker would therefore always need physical access to the speaker in order to exploit the vulnerability.
According to Kunze, there is no need to worry about a large number of other undiscovered vulnerabilities. According to the security researcher, Google’s Nest and Home devices are otherwise pretty well secured. In addition, in the event of a successful takeover, attackers could usually do no more than adjust a few basic settings.
Google recently unveiled a new design for its smart home app. You can find out what it looks like and how you can already join the beta version here:
more on the subject
Google shows major redesign for its smart home app
Is it weaknesses like these that make you shy away from the smart home? Or do you consciously take the risk like with other technology devices? Let us know what you think about the topic in the comments!



