Researchers say flaws in a popular GPS tracker, used with elderly or kids, can reveal real-time location and remotely activate its microphone, suggest recall
A popular GPS tracker — used as a panic alarm for elderly patients, to monitor kids, and track vehicles — contains security flaws … Tweets: @zackwhittaker and @zackwhittaker Tweets: Zack Whittaker / @zackwhittaker : Exclusive: Thousands of GPS trackers used to monitor kids and elderly patients can be remotely triggered to disclose their real-time location and can remotely activate its microphone. The researchers say there's no fix and the device should be recalled. https://techcrunch.com/... Zack Whittaker / @zackwhittaker : Obviously we tried it out using one @MabbsSec bought. Using just SMS, we located the device within meters of its location. With another command, you can call the device and listen in — without alerting anyone.
Context & Ripple Effects
This report extends a documented run of location-technology failures: a website bug at LocationSmart had already let anyone track people across North America without consent, and weeks before this story the Family Locator app left more than 238,000 users' real-time positions exposed on an unprotected server. What is new here is that the failure sits inside dedicated hardware sold specifically to protect the vulnerable — a panic alarm for elderly patients and a child monitor — and the researchers say there is no fix, only a recall.
The stakes are higher than in the earlier software cases because the attack surface includes the microphone: an attacker who can trigger location disclosure by SMS can also turn a safety device into a covert listening device. The same flaw class resurfaces three years later when BitSight finds Shenzhen-made Micodus vehicle trackers exploitable at scale on over a million cars, suggesting the 2019 findings were not an outlier but a template.
First-order effects
- Families and care providers relying on the tracker as a panic alarm lose their assurance immediately: with no patch available, the only safe action is to stop using the device, and the vendor faces a recall-or-liability decision on its flagship product.
- Anyone carrying the device — elderly patients, children, vehicles — is exposed right now to real-time location disclosure and remote microphone activation by anyone who knows the SMS command channel.
Second-order effects
- Distributors and resellers of low-cost white-label trackers face procurement scrutiny and potential liability, since the Micodus episode shows buyers cannot assume one vendor's flaw is isolated from the category.
- Competing tracker makers are pushed toward differentiated security claims — authenticated commands and updatable firmware — because 'no fix' headlines make the whole product category harder to sell to caregivers.
Third-order effects
- If the pattern holds — LocationSmart, Family Locator, this tracker, then Micodus — consumer location hardware drifts toward a recall-and-regulation regime like other physical safety products, where unpatchable devices are pulled from market rather than patched in place.
- SMS-based command channels become a recognized anti-pattern in device design, shifting the industry toward authenticated, signed firmware updates as a baseline requirement for any device that reports a person's whereabouts.
The trend: Consumer location-tracking products keep shipping with unauthenticated control channels, turning security failures into recalls rather than patches and inviting regulatory treatment of trackers as safety-critical hardware.