Researchers reveal Hello Barbie security vulnerabilities
Mattel's Hello Barbie doll could be hacked and young girls spied on, according to a US-based security researcher. S ecurity researcher Matt Jakubowski discovered t he WiFi-enabled Hello Barbie was vulnerable to hacking when storing audio files of conversations between kids and the doll in the cloud, on which they could be analysed by Mattel , its technology partner ToyTalk and other vendors. The hack allowed Jakubowski 'easy' access to the doll’s system information, account information, and stored audio files. The result might be that anyone could identify the individual and their home address and modify the doll to suit their needs. 'It’s just a matter of time until we are able to replace their servers with ours and have her say anything we want,' Jakubowski told NBC . Mattel software maker ToyTalk responded by saying it would patch the vulnerability. System 🤖 Mattel 🔗 Operator: Mattel/ToyTalk Developer: Mattel/ToyTalk Country: USA Sector: Consumer goods Purpose: Interact with children Technology: Voice recognition; NLP/text analysis Issue: Privacy; Security; Surveillance
- Date it happened
- 2015-11-01
- Organisation involved
- Mattel/ToyTalk
- Product, system or model
- Hello Barbie
This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.