Security Flaw in DJI ROMO Robot Vacuums Exposes Thousands to Privacy Breach

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A security vulnerability in DJI's ROMO robot vacuum cleaners allowed unauthorized remote control and real-time access to cameras and microphones on about 7,000 devices globally. The flaw, discovered by a developer, exposed sensitive user data and home layouts before DJI issued a fix.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (robot vacuum cleaners with autonomous navigation and cameras) whose malfunction (a security vulnerability in authentication) directly led to unauthorized access to sensitive personal data, violating users' privacy rights. This fits the definition of an AI Incident because the AI system's malfunction caused harm to individuals' rights and privacy. Although the company has remediated the issue, the harm occurred and is material. Therefore, this is classified as an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Robots, sensors, and IT hardwareDigital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rightsPsychological

AI system task:
Recognition/object detectionReasoning with knowledge structures/planning

In other databases

Articles about this incident or hazard