Security hole lets burglars knock out your smart home camera

Nest cameras could be vulnerable to Bluetooth-based attacks.
 By 
Brett Williams
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Smart home systems are supposed to make our lives easier and safer -- but some of the most popular connected security cameras could make your place an easy target if your neighborhood is visited by a tech-savvy burgling crew.

Security researcher Jason Doyle recently published a set of three vulnerabilities he found in Google's Nest cameras. The flaws, which take advantage of the camera system's always-on Bluetooth, allow anyone within the devices' Bluetooth Low Energy (BLE) range to overwhelm them and shut them down.

Doyle claims he reported the flaws to Google back in October when he first found them, but the company has yet to offer any updates to fix the issues. He decided to go public with the information last week to inform Nest users of their potential vulnerability.

Models affected by the vulnerabilities include the Dropcam, Dropcam Pro, Nest Cam Outdoor and Nest Cam Indoor running version 5.2.1 of Nest's firmware.

The first two flaws can be exploited by sending the camera overlong Wi-Fi SSID parameters or a encrypted password parameters. This triggers a buffer overflow condition, which causes the cameras to stop recording, crash and reboot.

The third flaw is a bit different: it knocks the camera from its connected Wi-Fi network entirely. Attackers can bombard the camera with a new SSID connect to, which knocks it off its network as it attempts to join the new one. The process takes about 90 seconds before the original Wi-Fi connection resets -- but if the attack is repeated on a loop, the security system is rendered useless.

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Doyle told us these flaws aren't all that rare in the smart products that are coming to our homes as the Internet of Things (IoT) grows and evolves. "I've recently been interested in how IoT products were implementing the newer Bluetooth LE specification," he said via email. "I tested several home automation products, from cloud cameras like Google's Nest Cam to Bluetooth-enabled pressure cookers; and my results were a bit disconcerting."

He said some connected home products that use Bluetooth don't have much to offer in the security department at all -- but the Nest isn't the worst of them. "The Nest cam does have some well-thought-out security measures in place but their implementation obviously had a few shortcomings," he said. 

Doyle also stressed that leaving Bluetooth on isn't the issue at hand here -- but it's important that makers of these connected devices lock those systems down.

"While leaving it on has functional advantages it also increases the attack surface and presents more options to an attacker," he said. "If they need it for some other integrations then it makes sense as long as they do their due diligence in securing the implementation."

A Nest rep acknowledged the existence of the flaws to us via email, but assured us a patch is on the way. "Nest is aware of this issue, developed a fix for it, and will roll it out to customers in the coming days," they said.

Until then, Nest owners would be smart to depend on the sturdiest old-school security systems their homes have to offer: a strong set of locks.

Mashable Image
Brett Williams

Brett Williams is a Tech Reporter at Mashable. He writes about tech news, trends and other tangentially related topics with a particular interest in wearables and exercise tech. Prior to Mashable, he wrote for Inked Magazine and Thrillist. Brett's work has also appeared on Fusion and AskMen, to name a few. You can follow Brett on Twitter @bdwilliams910.

Mashable Potato

Recommended For You
Siri bug reportedly delays Apple's smart home lineup
By Jack Dawes
Apple's New HomePod Now Available Within Its Stores

How AI is changing the modern smart home
retro futuristic artwork depicting home surrounded by smartphone and various widgets

Hacker says he accidentally breached 7,000 DJI robot vacuums with a PS5 controller
DJI Romo robot vacuum driving toward dock, tinted blue and red

Updating your security mindset: Keep your data private and your devices secure
By PCMag
Cyber Security

Webb telescope zooms in on a black hole's messy feeding zone
An artist's rendering of the Circinus galaxy's supermassive black hole

More in Tech
Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

The best smartwatch you've never heard of is on sale for less than $50
Nothing CMF Watch 3 Pro in light green with blue and green abstract background

Reddit r/all takes another step into the grave
Reddit logo on phone screen

Take back your screen from ads and trackers with this $16 tool
AdGuard Family Plan: Lifetime Subscription

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!