Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: humanoid-robot (1 article)Clear

Bluetooth flaw gives root on Unitree humanoid robots and can spread between them

A researcher disclosed two root remote code execution chains in the Unitree G1 humanoid robot, one reachable over Bluetooth from nearby without any pairing. Tracked as CVE-2026-76639 and CVE-2026-76640, the Bluetooth chain abuses a gap in Unitree's cloud service, which handed over another robot's key material to any free account without checking ownership, then used a buffer overflow in the Wi-Fi provisioning code to run code as root on the robot's control computer. The researcher demonstrated that a compromised robot can spread the exploit to another within Bluetooth range, making it wormable. There is no confirmed fixed firmware for the on-robot flaws, though the cloud ownership check was tightened.

Check
Owners of Unitree G1 robots should watch for firmware updates addressing these flaws, keep the robots off untrusted networks, and be aware that a nearby compromised unit could attack others over Bluetooth.
Affected
Unitree G1 humanoid robots (CVE-2026-76639, CVE-2026-76640); an attacker within Bluetooth range can chain a cloud key-recovery gap and a buffer overflow to gain root, and the exploit can spread robot to robot.
Fix
Isolate robots on segmented networks, limit physical and radio proximity by untrusted parties, apply firmware fixes when a confirmed release appears, and treat cyber-physical devices as full computers requiring patching.