Researchers find a bug in the ThroughTek Kalay SDK, which connects over 83M IoT devices with apps, that lets attackers access audio and video streams
A vulnerability in the Kalay platform leaves countless IoT devices susceptible to hackers. — A VULNERABILITY IS lurking in numerous types … Source: FireEye .
Context & Ripple Effects
The Kalay finding extends a research thread that keeps exposing how IoT devices share vulnerable plumbing. Researchers had already documented SweynTooth flaws crashing Bluetooth Low Energy devices like pacemakers in early 2020, then Amnesia:33 vulnerabilities in four open source TCP/IP stacks running on millions of embedded devices that December.
What makes Kalay different is the layer it sits on: not a radio protocol but a cloud-connect SDK that bridges more than 83 million devices to their companion apps — meaning a single flaw becomes an eavesdropping channel for whatever cameras and microphones ride through it. Weeks later, the same pattern surfaced again with BrakTooth's 16 Bluetooth firmware flaws across SoC boards from 11 vendors.
First-order effects
- ThroughTek and every device maker shipping the Kalay SDK face an urgent patch cycle, since attackers can access audio and video streams on affected devices today.
Second-order effects
- OEMs that bundled Kalay for its convenience now carry the reputational cost of a supplier's flaw, pushing device makers to demand security audits and faster disclosure terms from SDK vendors before integration.
Third-order effects
- If the pattern holds — one shared component exposing millions of branded devices at once — procurement and regulators will treat third-party SDKs as attack surface in their own right, forcing visibility into the software supply chain inside IoT products.
The trend: IoT security research is shifting up the stack from individual radios and firmware to the shared middleware and SDKs that quietly connect entire product categories.