Security researchers have uncovered widespread vulnerabilities in children's smartwatches and GPS-enabled car accessories, revealing that tens of millions of devices from numerous brands rely on a small number of insecure backend platforms, primarily based in Shenzhen, China. The flaws allow for surreptitious tracking, eavesdropping, and potential manipulation of these devices.
During a demonstration, researchers Vangelis Stykas and Felipe Solferini successfully tracked and monitored a reporter using a low-cost child's smartwatch. Despite a malfunctioning GPS feature, the device continuously transmitted Wi-Fi network identifiers, enabling precise location tracking. The researchers then remotely activated the watch's camera to capture photos as the reporter entered an elevator and sat at a desk. They also used the microphone to pick up audio, all without any indication on the watch itself that it was being accessed.
The smartwatch used in the demonstration was manufactured by YiQingTeng Electronics and sold under the brand CJC. It operates on the SETracker platform, which Stykas and Solferini identified as one of three major supply chains for GPS-enabled devices. Their analysis of over 70 such gadgets revealed that more than 30 brands of smartwatches and car trackers use the SETracker platform (also associated with Wonlex and Shenzhen 3G Electronics), while another 30-plus brands rely on the NewGPS2012 platform. A third significant platform, SinoTrack, also sells car trackers and smartwatches.
All three platforms were found to have significant security deficiencies. These vulnerabilities, in some cases as simple as a lack of authentication, could allow unauthorized access to devices. Specific risks identified include tracking a child's location, disabling or spoofing location data, intercepting and spoofing text and audio messages, replacing emergency contacts, silent audio eavesdropping, and capturing photos or videos from camera-equipped devices. For car accessories, the researchers noted the potential to track locations or spoof messages that could unlock or disable vehicles, though they did not test these capabilities on actual cars. Server-side vulnerabilities were also discovered, exposing consumer information and potentially allowing for remote code execution. One instance even suggested prior unauthorized access to a system's backend.
The researchers have been attempting to notify the companies behind these platforms for months. A representative for SETracker initially claimed the issues had been resolved but later stated that certain ports on their servers used by a "legacy" version of client systems had been blocked, forcing a "small subset of clients" to upgrade to protect "a small number of devices." SETracker confirmed that "the vulnerability has now been thoroughly remediated." However, SinoTrack and NewGPS2012 did not respond to inquiries, and the researchers indicated that their hacking techniques against those systems still appeared to be effective.
Stykas and Solferini emphasized that the apparent diversity of GPS devices on the market is largely an illusion, as many different consumer brands funnel data to the same vulnerable backend servers. They noted that a vulnerability in one backend can simultaneously affect dozens of consumer brands, making it difficult for consumers to identify which backend their product uses. For example, a "SafeKid" watch in Sweden and a "SaveFamily" watch in Spain might both send a child's location data to the same vulnerable myaqsh.com backend on Alibaba Cloud in mainland China. The researchers plan to present their full findings at the Black Hat cybersecurity conference.






