Alexa, Google Assistant Smart Speakers Can be Exploited for Phishing, Eavesdropping: Researchers

The issues were reported months ago, but they are reportedly yet to be patched.

Advertisement
By Nadeem Sarwar | Updated: 21 October 2019 18:52 IST
Highlights
  • Vulnerabilities can be exploited by malicious skill developers
  • Hackers can insert special characters to induce a long pause
  • They can send fake update messages to phish out passwords

Malicious parties can violate privacy via Alexa and Google Assistant voice apps

There has been a lot of debate lately regarding the privacy aspect when it comes to smart home devices, but it appears that the concerns are not unwarranted. Experts at Security Research Labs have uncovered vulnerabilities associated with Alexa and Google Assistant voice app backend systems that can be exploited to eavesdrop on users and for phishing out a password with ease. The security experts demonstrated the vulnerabilities in proof-of-concept videos and revealed how easy it is trick users into giving up sensitive information such as passwords and account details.

Security Research Labs explained in its report that malicious parties can use non-readable characters like a “�” in the code of voice apps for Amazon's Alexa assistant called Skills, or Actions in the case of Google Assistant. When such a character is encountered in the course of an ongoing interaction between users and the virtual assistant, it prompts a long pause, which tricks users into believing that the app has malfunctioned.

Advertisement

 

In such a scenario, users might think that the interaction has stopped and they need again to say a hotword like “Ok Google” or “Hey Alexa” to initiate an action. But in reality, the malicious party can use this pause to listen to whatever the user has said in the meanwhile, and can send the voice transcript of everything they said in a short duration to a dedicated server belonging to hackers.

Advertisement

Similarly, when the unreadable “�” character induces a short pause, say for 30 seconds to trick users into believing that something has malfunctioned, the malicious party can follow that up in their voice app with a code that reads a fake update message. In such cases, the false update voice prompt may ask users to say their password to install the update, and might also ask for more information such as the linked account. With this info, one can take control of an unsuspecting user's Amazon or Google account.

 

The eavesdropping and phishing vulnerabilities can be exploited via the backend that Google and Amazon provide to developers of Alexa skills and Google Assistant actions. And in the absence of stringent vetting protocols, malicious parties can gain access to functions that provide them access to critical commands and subsequently control how the virtual assistants behave. Security Research Labs reported the vulnerability to Google and Amazon months ago, but they are yet to be patched. Moreover, since Amazon and Google do not vet the code of app updates, malicious parties have a free hand here.

Advertisement

“All Actions on Google are required to follow our developer policies, and we prohibit and remove any Action that violates these policies. We have review processes to detect the type of behaviour described in this report, and we removed the Actions that we found from these researchers”, a Google spokesperson was quoted as saying by ZDNet regarding the issue, but Amazon is yet to issue a statement. Google also wants to spread awareness that the Google Assistant won't ask them for sensitive information such as a password via a voice skill, with the intention of keeping them aware of such deception.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. LG Expands TV Portfolio in India With New 115-inch QNED evo Mini LED TV
  2. Jio's New 3-In-1 Packs Bring Wi-Fi, TV, OTT Subscriptions Into One
  3. Vi Launches Three New Recharge Plans With Spotify Premium
  4. Amazon Great Freedom Sale 2026: Top Deals on Tablets Teased
  5. Boltt's First-Ever Smartphone to Launch in India on This Day
  6. iQOO Z11 Design, Colour Options Officially Teased Ahead of Launch in India
  7. This Snapdragon Chipset Could Power the New Honor Robot Phone
  8. OnePlus Independence Day Sale Brings Offers on OnePlus 15, Nord Series, More
  9. Nike Introduces Hybrid RN, Hybrid Fly Footwear System for Hybrid Athletes
  10. Redmi K100 Pro Will Launch With This Custom Snapdragon Chipset
  1. Nike Unveils Hybrid Footwear Lineup With Hybrid RN, Hybrid Fly for Multi-Discipline Training
  2. Asus Chromebook CX15 Launched in India With Intel N50, Google AI Features: Price, Features
  3. Redmi K100 Pro Confirmed to Feature Custom Snapdragon 8 Elite Gen 5 V Series Chip; Design Revealed
  4. Vodafone Idea (Vi) Bundles Spotify Premium With New Prepaid Plans; Prices Start at Rs. 230
  5. LG 2026 AI TV Lineup Launched in India With 115-inch QNED Evo, OLED Evo Models: Price, Specifications
  6. Dave Bautista Reportedly in Talks to Play Kratos in God of War Series; Amazon and Sony May Recast Atreus
  7. BlackRock Introduces Tokenised Money Market Funds for Stablecoin Reserves
  8. Honor Robot Phone Chipset, Battery and Other Key Features Tipped Ahead of August 12 Launch
  9. iPhone 18e Could Get More RAM to Power Apple Intelligence, Leak Suggests
  10. Google Pixel 11 Pro Fold Design Revealed as Made by Google Launch Event Draws Close
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.