Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringembedded-device-vulnerabilitybreach-disclosure-notificationendpoint-software-vulnerability

Security exposures in consumer and mobile apps: robot vacuum account takeover and widespread mental-health app flaws

Updated 3mo agoFirst seen Feb 24, 20264 sources

A security flaw in DJI Romo robot vacuums allowed unauthorized access to thousands of devices after a user reverse-engineered the device-to-cloud protocol to build a custom controller app. By obtaining the private token for their own vacuum, the researcher reported they could access backend servers across regions and inadvertently gained control of roughly 6,700 vacuums, with potential access to floor plans, live camera/microphone feeds, and remote control functions; DJI issued server-side/firmware updates that required no user action, though the researcher reported at least two issues remained (including video streaming without a PIN and another undisclosed high-severity problem). Separately, mobile security researchers reported that popular Android mental health apps (about 14.7M installs across ten apps) contained 1,575 vulnerabilities—mostly low/medium severity but including 54 high-severity findings—creating risk of exposure of sensitive therapy data via issues such as credential interception, notification spoofing, HTML injection, and user location leakage.

Optimizely also confirmed a data breach following a vishing (voice-phishing) attack that provided attackers access to some internal systems and resulted in theft of basic business contact information from internal business systems/CRM and limited back-office documents; the company said attackers could not escalate privileges, install software, or establish backdoors, and it reported no evidence of access to sensitive customer data beyond contact details. While the Optimizely incident is distinct from the consumer-device and mobile-app vulnerability disclosures, it reinforces the operational risk of social engineering and the likelihood of follow-on phishing using stolen contact data.

Share:
Security exposures in consumer and mobile apps: robot vacuum account takeover and widespread mental-health app flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 23, 20264mo ago

Mental health app findings disclosed during coordinated vendor notification

By late February 2026, Oversecured had privately notified affected vendors about the vulnerabilities in the 10 Android mental health apps while withholding app names during coordinated disclosure. Public reporting said remediation status was still unclear and that the apps collectively had more than 14.7 million installs.

DJI remediates reported robot vacuum server-side security issue

After Azdoufal reported the vacuum access issue, DJI deployed updates that remediated the flaw without requiring user action. The researcher said some problems still remained, including the ability to stream video without a security PIN and another undisclosed severe issue.

Researcher discovers broad access flaw in DJI Romo robot vacuums

While reverse engineering his own DJI Romo robot vacuum to control it with a PlayStation controller, Sammy Azdoufal uncovered a security flaw that exposed access to roughly 6,700 vacuums worldwide. The issue allowed retrieval of floor plans, access to live camera and microphone feeds, and remote control of devices across regions including the U.S., Europe, and China.

Jan 22, 20265mo ago

Oversecured scans 10 Android mental health apps and finds 1,575 flaws

On January 22–23, 2026, mobile security firm Oversecured analyzed 10 popular Android mental health apps from Google Play and identified 1,575 vulnerabilities, including dozens of high-severity issues. The flaws affected areas such as local storage, authentication, inter-app communication, encryption, and backend connectivity, with potential exposure of sensitive therapy and medical data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
2 linked
Claude CodeHome-Assistant
Organizations
9 linked
BleepingComputerGoogleOversecuredTinesDjiVox MediaFuture plciLifeSony Group Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Security exposures in consumer and mobile apps: robot vacuum account takeover and widespread mental-health app flaws | Mallory