UniBLEed: Root RCE on Any Unitree G1 Humanoid Robot
Root on a $20,000 humanoid robot from Bluetooth range. One chain crossing Bluetooth, Unitree’s cloud, mobile, and the firmware running the G1 itself. Here’s the complete technical breakdown of the $6,700 bounty and two CVEs it produced: CVE-2026-76639 / CVE-2026-76640.
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range Root on a $20,000 humanoid robot from Bluetooth range. One chain crossing Bluetooth, Unitree’s cloud, mobile, and the firmware running the G1 itself. Here’s the complete technical breakdown of the $6,700 bounty and two CVEs it produced: CVE-2026-76639 / CVE-2026-76640. Root on a $20,000 humanoid robot, via a cloud API that decrypts any G1's AES key from any free Unitree account without checking ownership. One BLE characteristic that accepts writes without pairing. A heredoc injection that hijacks…
saved by
related reading
- GitHub - Bin4ry/UniPwn at boschko.cagithub.com
- Open X-Humanoidgithub.com
- Unrestricted AI API + Enterprise Policy Gateway | abliteration.aiabliteration.ai
- Training a Misaligned Reward Seekeralignment.anthropic.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Humanoid Atlas | Humanoid Robot Supply Chain Map, OEM Database & Industry Analysishumanoids.fyi
- Security incident disclosure — July 2026huggingface.co
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- Multiple Vulnerabilities in Rocket Software UniData's UniRPC server (Fixed) | Rapid7 Blograpid7.com
- Alec Petridis - my projectsxz.ax
- Lakera – Test your AI hacking skillsgandalf.lakera.ai
- An alignment assessment of recent cybersecurity incidentsanthropic.com