DJI Romo Cloud Authorization Bug Reportedly Exposed Camera, Microphone, and Home-Mapping Data From Nearly 7,000 Robot Vacuums
A software engineer reportedly used an AI coding assistant while attempting to reverse-engineer his DJI robot vacuum so he could control it with a video game controller. In the course of that work, he reportedly said he discovered that credentials used to communicate with DJI's cloud servers could also grant access to data associated with nearly 7,000 other vacuums across 24 countries, including live camera feeds, microphone audio, maps, and status information.
- Date it happened
- 2026-02-08
- Organisation involved
- DJI
- Product, system or model
- In-home sensor data, DJI Romo, DJI Home app, DJI cloud servers
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.