Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ars Technica Security

Web portal leaves kids' chats with AI toy open to anyone with Gmail account

  • What: A web portal associated with the Bondu AI toy had an information disclosure vulnerability.
  • Why: The portal allowed anyone with a Gmail account to access transcripts of children's conversations with the toy.
  • Impact: Unauthorized access to sensitive data, raising privacy concerns for children and their families.
Read Full Article →

Earlier this month, Joseph Thacker's neighbor mentioned to him that she'd preordered a couple of stuffed dinosaur toys for her children. She'd chosen the toys, called Bondus, because they offered an AI chat feature that lets children talk to the toy like a kind of machine-learning-enabled imaginary friend. But she knew Thacker, a security researcher, had done work on AI risks for kids, and she was curious about his thoughts. So Thacker looked into it. With just a few minutes of work, he and a web security researcher friend named Joel Margolis made a startling discovery: Bondu’s web-based portal, intended to allow parents to check on their children's conversations and for Bondu’s staff to monitor the products’ use and performance, also let anyone with a Gmail account access transcripts of virtually every conversation Bondu's child users have ever had with the toy. Without carrying out any actual hacking, simply by logging in with an arbitrary Google account, the two researchers immediately found themselves looking at children's private conversations, the pet names kids had given their Bondu, the likes and dislikes of the toys' toddler owners, their favorite snacks and dance moves. Read full article Comments

Share this article