A Shark vacuum security flaw could allow attackers to access camera feeds, WiFi passwords, and maps of users’ homes, according to a security researcher.
The reported issue affects robot vacuums made by SharkNinja. It allegedly stems from a weakness in the devices’ AWS Internet of Things configuration and remains unpatched more than 90 days after private disclosure.
However, an attacker would first need physical access to a vulnerable vacuum. This requirement makes the attack less likely for most users, although it remains a concern for owners of affected devices.
Flaw Could Turn Robot Vacuums Into Surveillance Tools
The Shark vacuum security flaw was discovered in March 2026 by a researcher known as Tokay0.
The researcher examined a Shark RV2320EDUS robot vacuum and found an embedded AWS IoT certificate inside the device. According to the report, an attacker who extracts this certificate could use it to communicate with other vulnerable SharkNinja devices in the same AWS region.
That access could reportedly expose live camera functions, saved WiFi credentials, and maps created as the vacuum moves through a home.
As a result, a compromised robot vacuum could reveal sensitive details about a household, including room layouts and wireless-network information.
AWS IoT Certificate Creates the Risk
The reported issue involves the Message Queuing Telemetry Transport protocol, commonly known as MQTT. Internet-connected devices often use this lightweight messaging protocol to exchange commands and status updates.
In this case, the researcher claims that a certificate taken from one Shark vacuum can authenticate with other devices that use the same AWS Cloud region.
AWS regions are geographically separate. Therefore, a certificate linked to one region would not automatically provide access to devices elsewhere in the world.
Still, the researcher said an attacker could potentially purchase devices connected to specific regions, extract their certificates, and then target other devices within those regions.
Hundreds of Thousands of Devices May Be Exposed
During a 24-hour observation period, the researcher reportedly identified around 673,000 SharkNinja devices in one AWS region. More than 1.5 million unique devices were reportedly observed in that same region.
If similar exposure exists across other AWS regions, the number of potentially affected devices could reach into the millions. However, the full scope of the Shark vacuum security flaw has not been independently confirmed.
The research focused on the Shark RV2320EDUS and AV1102ARUS models. Nevertheless, other Shark robot vacuums may also use similar configurations.
SharkNinja sells a wide range of connected household devices, including robotic vacuums, air purifiers, and kitchen appliances.
Researcher Says the Issue Remains Unpatched
Tokay0 said the vulnerability was privately reported to SharkNinja before the public disclosure. According to the researcher, the company initially said it was working on the matter but did not provide further details after several follow-up attempts.
The researcher then published the findings after waiting more than 90 days.
SharkNinja had not publicly confirmed the vulnerability at the time of reporting. Therefore, users should treat the technical claims as unverified until the company issues a statement or releases a security update.
Physical Access Limits the Attack
The Shark vacuum security flaw is serious because it could expose highly personal household information. Still, exploiting it reportedly requires an attacker to physically obtain and disassemble a vulnerable device first.
That step raises the barrier to entry. It means the attack is more likely to be used by technically skilled individuals than by opportunistic cybercriminals.
Owners of Shark robot vacuums should watch for firmware updates and review the permissions granted to their devices. They should also use a strong, separate password for their home WiFi network and keep connected appliances on an isolated guest network where possible.


0 responses to “Shark Vacuum Security Flaw Could Expose Cameras and WiFi”