A security researcher, Olivier Laflamme, discovered critical vulnerabilities in the Unitree G1 humanoid robot that allow for remote root access. By exploiting two vulnerabilities (CVE-2026-76639 and CVE-2026-76640), Laflamme showcased a method to compromise the robot without physical access. The first vulnerability involves accepting unsafe file uploads via Ethernet, leading to unauthorized command execution.
The second flaw allows for Bluetooth unpairing attacks to access a decryption key from Unitree's cloud, enabling attackers to control other nearby robots. Laflamme's research highlights the potential for these compromised robots to spread attacks to others, raising concerns for environments where multiple G1s operate close together. Unitree's prompt response included patching the flaws and offering a bounty for the bugs discovered.