Researchers show how malicious voice apps for Alexa or Google Home eavesdrop on users, as Amazon and Google take a lax approach to vetting the platforms
Exclusive: Amazon, Google fail to address security loopholes in Alexa and Home devices more than a year after first reports.
Context & Ripple Effects
This story extends an established line of research on voice-assistant attack surfaces: back in 2017, researchers showed every popular assistant could be hijacked via ultrasonic commands played through cheap hardware, and by mid-2019 Google was admitting one of its own language reviewers had leaked confidential Dutch audio. What is new here is the vector — not hardware tricks or insider leaks, but malicious third-party voice apps that pass Amazon's and Google's vetting outright.
The more damning detail is the timeline: the description says the platforms failed to close these loopholes more than a year after first reports, which frames the flaw as a governance choice rather than a one-off bug. The subsequent arc bears this out — a December 2019 investigation found all four major vendors leaning on contractors for voice transcriptions, and in August 2020 researchers disclosed another Alexa bug that could have handed over personal data before it was patched.
First-order effects
- Users who install skills on Alexa or Google Home are exposed to apps that can eavesdrop on conversations despite clearing both companies' review processes, with Amazon and Google leaving the vetting gaps open a year after first reports.
Second-order effects
- Legitimate skill developers now compete against a trust deficit they did not create — every disclosed eavesdropping app makes users and brands warier of the entire third-party skill catalog, pressuring Amazon and Google toward stricter (and slower) review regimes.
- The disclosure lands alongside mounting scrutiny of how these vendors handle voice data generally, from contractor transcription practices to law-enforcement use of speaker records, compounding reputational costs for the same two platform owners.
Third-order effects
- If lax vetting persists as third-party ecosystems grow, voice assistants risk following mobile app stores' trajectory: security incidents eventually forcing regulator involvement and formal certification requirements for voice-app marketplaces.
- Combined with law enforcement's growing use of smart-speaker data in investigations, unvetted listening apps blur the line between criminal exploit and lawful access — making the microphone itself the contested surface of the smart home.
The trend: Voice platforms are scaling third-party app ecosystems faster than their security vetting and data-handling governance mature, turning consumer living rooms into an ongoing test case for ambient-computing trust.