/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers show how malicious voice apps for Alexa or Google Home eavesdrop on users, as Amazon and Google take a lax approach to vetting the platforms

Exclusive: Amazon, Google fail to address security loopholes in Alexa and Home devices more than a year after first reports.

ZDNet Catalin Cimpanu

Context & Ripple Effects

This story extends an established line of research on voice-assistant attack surfaces: back in 2017, researchers showed every popular assistant could be hijacked via ultrasonic commands played through cheap hardware, and by mid-2019 Google was admitting one of its own language reviewers had leaked confidential Dutch audio. What is new here is the vector — not hardware tricks or insider leaks, but malicious third-party voice apps that pass Amazon's and Google's vetting outright.

The more damning detail is the timeline: the description says the platforms failed to close these loopholes more than a year after first reports, which frames the flaw as a governance choice rather than a one-off bug. The subsequent arc bears this out — a December 2019 investigation found all four major vendors leaning on contractors for voice transcriptions, and in August 2020 researchers disclosed another Alexa bug that could have handed over personal data before it was patched.

First-order effects

  • Users who install skills on Alexa or Google Home are exposed to apps that can eavesdrop on conversations despite clearing both companies' review processes, with Amazon and Google leaving the vetting gaps open a year after first reports.

Second-order effects

  • Legitimate skill developers now compete against a trust deficit they did not create — every disclosed eavesdropping app makes users and brands warier of the entire third-party skill catalog, pressuring Amazon and Google toward stricter (and slower) review regimes.
  • The disclosure lands alongside mounting scrutiny of how these vendors handle voice data generally, from contractor transcription practices to law-enforcement use of speaker records, compounding reputational costs for the same two platform owners.

Third-order effects

  • If lax vetting persists as third-party ecosystems grow, voice assistants risk following mobile app stores' trajectory: security incidents eventually forcing regulator involvement and formal certification requirements for voice-app marketplaces.
  • Combined with law enforcement's growing use of smart-speaker data in investigations, unvetted listening apps blur the line between criminal exploit and lawful access — making the microphone itself the contested surface of the smart home.

The trend: Voice platforms are scaling third-party app ecosystems faster than their security vetting and data-handling governance mature, turning consumer living rooms into an ongoing test case for ambient-computing trust.

Discussion

  • @bad_packets @bad_packets on x
    “@SecReLabs discovered that by adding the ‘�. ’ (U+D801, dot, space) character sequence to various locations inside the backend of a normal Alexa/Google Home app, they could induce long periods of silence during which the assistant remains active.” https://www.zdnet.com/...
  • @fabiochiusi Fabio Chiusi on x
    “We now show that, not only the manufacturers, but... also hackers can abuse those voice assistants to intrude on someone's privacy” https://twitter.com/...
  • @evacide Eva on x
    As foretold by prophecy, Alexa and Google Home are being used to eavesdrop and phish passwords. https://arstechnica.com/...
  • @mehdishibahara Mehdi Shibahara on x
    “After about a minute, the apps use a voice that mimics the ones used by Alexa and Google home to falsely claim a device update is available and prompts the user for a password for it to be installed.” Never do that! https://twitter.com/...