← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 29, 2026 · 11:55via Security Affairs

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

Brief

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby.

Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable.

In his technical write-up , he details two vulnerabilities, CVE-2026-76639 and CVE-2026-76640, that can be chained across Bluetooth, Unitree’s cloud infrastructure, the mobile app, and the robot’s firmware to gain unauthenticated root access to any G1 within Bluetooth range.

The first bug lives entirely inside the robot itself, no wireless attack surface needed if you can reach it over Ethernet.

Read more on Security Affairs