HeadlinesBriefing favicon HeadlinesBriefing.com

Hackers Hijack Kids' Smartwatches for Stalking

Hacker News •
×

Security researchers Stykas and Felipe Solferini demonstrated at Black Hat how a $30 CJC smartwatch for kids could be hijacked to silently track a reporter's location across Brooklyn and Manhattan, capture photos via its camera, and record audio from its microphone—all without any visible indication on the device. The watch, manufactured by Yi Qing Teng Electronics in Shenzhen, transmitted nearby Wi-Fi identifiers to a remote server, enabling precise location tracking even when GPS malfunctioned.

Their analysis of over 70 GPS-enabled watches and car accessories revealed that more than 30 brands rely on Yi Qing Teng's SETracker platform, another 30-plus use New GPS2012, and a third major supply chain, Sino Track, serves car trackers and smartwatches. Combined, these three Shenzhen-based platforms power tens of millions of devices, all sharing critical security flaws: missing authentication, SQL injection vulnerabilities, and the ability to spoof locations, intercept messages, replace emergency contacts, and silently activate cameras and microphones.

The researchers warn that the white-label model creates an illusion of choice—parents in different countries buying different brands unknowingly send children's data to the same vulnerable backends on Alibaba Cloud in mainland China. Despite months of disclosure, fixes remain incomplete; only hours before their presentation did SETracker exploits stop working, while Sino Track and New GPS2012 vulnerabilities persist.