Home Wiki

Shark robot vacuum

Last updated View on consumerrights.wiki ↗

Contents3
  1. Overview
  2. Security
  3. References
Shark robot vacuum
[[File:|200px]]
Basic Information
Release Year
Product Type Robot vacuum
In Production Yes
Official Website https://www.sharkninja.com/vacuums-air-care/vacuum-cleaners/robot-vacuums

Shark robot vacuums are the cloud-connected robotic vacuum cleaners SharkNinja sells under its Shark brand, controlled through the SharkClean phone app.[1] In 2026 a security researcher showed that a flaw in how every internet-connected Shark vacuum logs in to Amazon Web Services let an outsider take over the machines across an entire cloud region and, on camera-equipped models, reach the live camera feed, the stored home map, & the home Wi-Fi password; SharkNinja had not patched it at disclosure.[1][2]

Overview

Shark robot vacuums are part of SharkNinja's Cleaning Appliances category, which includes its robotics products.[3] Each internet-connected unit keeps a permanent connection to a server run by Amazon Web Services so the owner can start, stop, schedule, & steer the machine from the SharkClean app, & camera-equipped models stream mapping & camera data to that cloud.[1][4] SharkNinja's Connected Devices Privacy Notice tells owners that Images from the camera stay on your machine and are not accessed by SharkNinja.[4]

Security

Main article: Shark robot vacuum cloud vulnerability (2026)

A researcher publishing under the handle tokay0 reported to SharkNinja on March 1, 2026 that Shark robot vacuums authenticate to Amazon's cloud with a device certificate SharkNinja never locked to the individual machine, so a certificate copied off one vacuum is accepted as valid for commands aimed at any Shark vacuum in the same cloud region.[1][2] On camera-equipped models the flaw exposed the live camera feed, the stored home map, & the Wi-Fi password held on the device as readable text.[1][2] tokay0 published the still-unpatched flaw on July 13, 2026; the researcher stated that all internet-connected Shark vacuums are affected.[1][2]

References

  1. 1.0 1.1 1.2 1.3 1.4 1.5 tokay0 (2026-07-13). "No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE". tokay0.com. Archived from the original on 2026-07-18. Retrieved 2026-07-19.{{cite web}}: CS1 maint: numeric names: authors list (link)
  2. 2.0 2.1 2.2 2.3 Khandelwal, Swati (2026-07-16). "Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide". The Hacker News. Retrieved 2026-07-19.
  3. SharkNinja, Inc. (2026-03-02). "Form 10-K for the fiscal year ended December 31, 2025". U.S. Securities and Exchange Commission. Retrieved 2026-07-19.
  4. 4.0 4.1 SharkNinja. "Connected Devices Privacy Notice". SharkNinja. Retrieved 2026-07-19.