It was recently discovered that Google Home speakers were vulnerable to hackers who could potentially conduct eavesdropping attacks.
Trust is an integral part of owning a smart speaker, as it requires you to trust the company behind it with your voice recordings and the noises of your home. Unfortunately, computers often have numerous vulnerabilities that can be exploited – Google Home are no different. A researcher recently discovered a way to secretly listen in on nearby Google Home!
During our observation, security expert Matt Kunze found that setting up a Google Home with a personal Google was incredibly simple and provided an impressive array of tools to the user. Once an account is created, users can control smart home gear, seamlessly initiate routines, and even make phone calls directly from their device!

See also: EarSpy attack tracks Android phones via motion sensors
Kunze was curious to find out if it would be possible to link a new Google account to a Google Home speaker . To his surprise, he found that, even without access to the Wi-Fi network the speaker is connected to, it was actually quite easy. This process can be carried out remotely, by bringing up the Google Home setup feature and adding another separate Google account before reconnecting to the target's Wi-Fi network
In more detail, you can see the attack process below, which is also listed on the researcher's blog:
- The attacker wishes to secretly monitor (eavesdropping attack) the victim when they are in close proximity to a Google Home device without having access to the target's Wi-Fi password
- The attacker can locate their victim's Google Home device by searching for MAC addresses with a specific prefix associated with Google Inc. (e.g. E4:F0:42).
- The attacker's malicious intent is to send deauth, disconnecting the victim device from its network and forcing it into a setup state.
- The attacker connects to the device's installation network and requests its credentials (including name, credentials, and cloud).
- The attacker connects to the internet and exploits the device's information to link his profile to that of the victim.
- With the advent of such technologies, malicious actors can now use a victim's Google Home device to spy on them remotely – no physical proximity is required.
To bring the research to life, the researcher has published three PoCs for these activities on GitHub. But don't worry, they won't work on Google Home devices running the latest firmware . The PoCs serve a much broader purpose than simply introducing malicious users, and can allow attackers to spy on microphones, make arbitrary HTTP over victims' networks, and read or write any type of file located on the device.

If a hacker wants to eavesdrop on Google Home , they’ll be able to manipulate switches, play music, and control appliances. On top of that, they could also initiate phone calls through the smart home device and record all the activities taking place in the victim’s home without them having any idea. During the call, there are usually indicators like the lights turning blue – but unfortunately for those who aren’t familiar with this feature or for everyday users who might just think their speaker is busy with something else, like an update, these indicators can easily go unnoticed!
See also: ALPHV BlackCat: Clones victim's site for data leak
After first uncovering the issue in January 2021, Kunze reported it to Google in March. As a result of his discovery and reporting, Google has since responded by paying over $100,000 and fixing the issue. It is no longer feasible to add an account to your Google Home remotely — although you can still enable the setup feature remotely. Additionally, phone calls like the ones made in the video can no longer be included as part of routines due to this update.
Google 's brilliant smart displays are even more secure because they display a QR code during setup. This ensures that the setup network is protected with WPA2 , so an attacker would need physical access to the device to connect it to their account.
For those who don't know, an eavesdropping attack is a form of digital security breach that involves someone intercepting and monitoring your data without your knowledge. It can be used to compromise confidential data, such as passwords, credit card numbers, and other sensitive information.
Despite the potential for eavesdropping , the security researcher firmly believes that Nest and Home devices are incredibly secure overall and don't offer many opportunities for attack. According to him, the flaws he found were quite subtle - usually all a malicious actor could do is change some basic settings.
Source: androidpolice.com
