← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 28, 2026 · 09:36via CyberPress

Unitree G1 Humanoid Robot Flaws Enable Unauthenticated Root RCE Over Bluetooth

Brief

A newly disclosed flaw in Unitree’s G1 humanoid robot could allow an attacker standing nearby to obtain unauthenticated remote code execution as root via Bluetooth Low Energy (BLE).

The research, dubbed UniBLEed, targets the robot’s Locomotion PC, a Linux-based system that supports safety-critical operations including motors, cameras, audio, and voice.

The Bluetooth attack chain, tracked as CVE-2026-76640, begins with GATT characteristic 0xFFE2. The interface accepted writes using only basic WRITE permissions, enabling a device within radio range to communicate with the robot without BLE pairing or authentication.

Unitree G1 Humanoid Robot Flaws

A plaintext bootstrap request then returned a robot-specific AES-128 key inside an RSA-encrypted response.

Read more on CyberPress