How to hack Xplora smartwatches (for kids): Into 1.5 million devices in the EU via HTTPS & MQTT. ⌚👶🏻☁️👨🏻💻☠️
Security researcher Nils Rollshausen publicly presents his analysis of the Xplora smartwatch for kids, which is currently being actively advertised in the EU and the US as a robust, secure, “privacy made in Europe” type of solution.
The watch uses Android OS, so the author explores the internals of the device using the ADB shell, analyzes the communication, and... finds ways to take over 1.5 million devices sold so far. Using only the IMEI.
So, what can an attacker do?
Send messages to watches, communicating with kids while pretending to be a “parent”
Extract data in bulk, including contacts and messages
Make kids disappear by resetting the watch
Send spam and ads
Enjoy the read - this is very interesting research. Also, maybe take this watch away from your kids until the manufacturer fixes those vulnerabilities. And please share it with anyone who may be using Xplora - IMO, this is important.
Stay safe!
More details:
Watch Your Kids [PDF]: https://troopers.de/downloads/troopers26/TR26_Watch_Your_Kids_8MDPWZ.pdf
Xplora Unlocker [Online Tool] https://rec0de.net/open/xplora/


