UniBLEed: Wormable Bluetooth RCE Gives Root on Any Unitree G1 Humanoid
jedisct1 · x · 2026-08-28
Researcher Olivier Boschko published UniBLEed: an unauthenticated, fully wormable root RCE affecting any Unitree G1 humanoid within Bluetooth range — once one G1 is compromised, it can spread the exploit to the next indefinitely.
The chain crosses Bluetooth, Unitree's cloud, mobile, and firmware: a cloud API that decrypts any G1's AES key from any free account without ownership checks; a BLE characteristic accepting writes without pairing; a heredoc injection hijacking WiFi; a path traversal in the robot's chatbot knowledge base leaking the binary's load address; and a 1050-byte BSS buffer overflow that corrupts the event loop into calling system() as root. Disclosure went from 3 months to 80 minutes reproducible, earning $6,700 in bounties and two CVEs (CVE-2026-76639 / 76640).
Notably, Unitree's security team even sent the researcher a G1 as payment for prior work — virtually unheard of in robotics.
More from Embodied
- 8.64s Robot Overtakes Field After Slow Start in Race — TansuYegen · 2026-08-28
- China Demonstrates Flying Taxi That Lands Outside Office Buildings — TansuYegen · 2026-08-28
- SkildAI releases S1, a robotics foundation model for one-shot learning — deepakpathak · 2026-08-28
- S1 Robot Demo: Zero-Finetuning Execution of New Tasks from One Video — deepakpathak · 2026-08-28
- Google launches Pokémon-themed Fitbit Air with sleep tracking — yungcontent · 2026-08-28
- Timothy Lee bets against home humanoid robots before 2029, sees only teleoperated pilots — binarybits · 2026-08-28