Security researcher Jerry Gamblin has revealed how a few lines of code written in XML on the Google Home Hub can be used to gain unauthorized access to user data. This code can exploit a vulnerable API and force the device to reboot or reveal user data.

Gamblin wrote in a post that he found a number of open ports used by the device. Out of curiosity, he opened the command prompt on his computer to check the security of the Google Home Hub.
What he found was quite shocking, as he found that it is possible to force the Home Hub to reboot with a single line of code. After some code experimentation, Gamblin was able to delete the Google Home Hub's existing WiFi networks and disable notifications.
Google, however , doesn't seem to be concerned about the issue. As its spokesperson stated, the APIs mentioned by Gamblin "are used by mobile apps to configure the device and are only accessible when the apps and the Google Home device are on the same Wi-Fi." The Google spokesperson also added that "despite what has been claimed, there is no evidence that user information is at risk."
Although the attacker would have to connect to the same Google Hub network they are targeting, Google would have to come up with other forms of identity verification to prevent people with malicious intent from executing such code.
