Back to all news
Security

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News·August 28, 2026·1 min read
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Security researcher Olivier Laflamme disclosed two root remote code execution chains affecting the Unitree G1 EDU humanoid robot, including a Bluetooth Low Energy path reaching root on the Locomotion PC. Tracked as CVE-2026-76639 and CVE-2026-76640, the first flaw involves a network-adjacent path through chat_go and bashrunner. The vulnerabilities allow full system compromise.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store