Threat Intelligence

Root-Level Flaws in Unitree G1 Robots Highlight Growing IoT Attack Surface

The Hacker News · 28 Aug 2026
Key Takeaway Any connected device — including robots, IoT hardware, and Bluetooth-enabled equipment — should be inventoried, kept updated, and isolated from critical business networks.

Security researcher Olivier Laflamme has disclosed two separate vulnerability chains in the Unitree G1 EDU humanoid robot that allow attackers to achieve root-level remote code execution — the highest level of control over a device. Tracked as CVE-2026-76639 and CVE-2026-76640, the flaws affect the robot's Locomotion PC, the onboard computer responsible for controlling movement.

The first vulnerability involves a network-adjacent attack path through internal software components (chat_go and bashrunner), while the second can reportedly be triggered over Bluetooth Low Energy (BLE), a wireless protocol commonly used for short-range device pairing. This means an attacker within Bluetooth range, without direct network access, could potentially compromise the robot and take full control of its underlying system.

While humanoid robots like the Unitree G1 EDU are primarily used in research, education, and industrial settings rather than typical small business environments, this disclosure is a reminder that increasingly common 'smart' and robotic devices carry the same security risks as traditional IT systems. Businesses experimenting with connected robotics, IoT devices, or Bluetooth-enabled equipment should treat them as part of their attack surface, not as isolated novelty tools.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.