Beautiful Virgin Islands

Tuesday, Mar 24, 2026

Amazon Alexa security bug allowed access to voice history

Amazon Alexa security bug allowed access to voice history

A flaw in Amazon's Alexa smart home devices could have allowed hackers access personal information and conversation history, cyber-security researchers say.

Attackers could install or remove apps on a device without the owner knowing, Check Point Research reports.

The hack "required just one click on an Amazon link" purposely crafted by the attacker, it says.

The firm told Amazon about the flaw, which has now been fixed.

Amazon said: "The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us."

It said it did not know of any case where a bad actor had used the vulnerability to target its customers.

In January, Amazon said there were "hundreds of millions" of Alexa devices in the world.

Malicious skills


Check Point said the hack required the creation of a malicious Amazon link, which would be sent to an unsuspecting user.

Once they clicked the link, the attacker could get a list of all installed Alexa "skills" - or apps - and steal a token allowing them add or remove skills.

One way to use the flaw would be to remove a skill and then install a malicious one that uses the same "invocation phrase" - the series of spoken words used to trigger it. This could have been done without the user knowing.

The next time the user tried to activate that skill, it would have run the attacker's app instead.

The attackers would have been able to see Alexa's voice history - a record of conversations between the user and device.

Check Point said this could create major problems, pointing to banking skills that let the user check their account balance.

"This could lead to exposure of personal information, such as banking data history," they argued - even though it does not save banking login details.

Amazon objected to this suggestion, however, saying that banking information - like balances - was redacted in the record of Alexa's responses, so it could not have been accessed.

The attack would also allow access to personal information in the Amazon profile, such as a home address, Check Point said.

Amazon also said it believed the use of a secret malicious skill was less likely than Check Point's researchers implied.



Amazon’s head of Alexa Dave Limp on privacy concerns



It said there were systems in place to prevent malicious skills from ever hitting the Alexa Skills Store - and that security reviews were part of their process.

Badly behaving apps were also routinely deactivated, it said.

"Their screening process probably would have caught most bad actors - they are quite good at that and know their reputation is at stake," said University of Surrey cyber-security expert Prof Alan Woodward.

"The thing about this hack was that it was due to a vulnerability that is well-known… so it's surprising to see it in Amazon's estate."

He said the access to voice records was a big concern, but was unsure if other hackers could have known about the vulnerabilities in specific subdomains used to launch the attack.

"Although if the security researchers found it, I'm sure less scrupulous people could have done the same."

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
UK Police Investigate Targeted Attack on Jewish Ambulance Vehicles
UK Police Investigate Targeted Attack on Jewish Ambulance Vehicles
Senior UK Advocate Criticises Barnhart Retirement Appointment, Calls for Reconsideration
UK Finds No Evidence of Direct Iranian Threat to Britain, Says Prime Minister Starmer
Assessing Iran’s Strike Capability and the UK’s Readiness Amid Rising Tensions
NATO Unable to Confirm Iran’s Role in Strike on UK-US Base as Tehran Denies Involvement
University of Kentucky’s Youling Xiong Receives SEC Faculty Achievement Award for 2026
Trump Highlights Satirical Portrayal of UK Leadership Amid Talks with Prime Minister Starmer on Iran Conflict
Trump Highlights Satirical Portrayal of UK Leadership Amid Talks with Prime Minister Starmer on Iran Conflict
UK Fuel Prices Surge Toward Crisis Levels as Experts Warn of Further Sharp Increases
UK Fuel Prices Surge Toward Crisis Levels as Experts Warn of Further Sharp Increases
Duchess of Sussex Secures ‘As Ever’ Trademark Rights in Australia Ahead of High-Profile Visit
UK Reaffirms Security as Officials Reject Claims of Immediate Iranian Missile Threat
Rising Middle East Tensions Spark ‘Trumpflation’ Debate Over Impact on UK Households
UK Minister Says No Evidence Iran Can Strike Europe Despite Heightened Warnings
British-Iranians Voice Safety Concerns to Authorities as Regional Conflict Intensifies
Confirmed Meningitis Cases Linked to Kent Outbreak Revised Down to Twenty
UK Government Sees No Evidence Iran Can Strike London Amid Rising Regional Tensions
Debate Grows Over Recognition of Indigenous Cultural Icons in the United Kingdom
Iran Missile Launch Toward Diego Garcia Raises Questions After Failed Strike on US–UK Base
Donald Trump Amplifies Viral Satirical Clip Highlighting UK–US Political Dynamics
UK Satirical Show Draws Attention with Sketch Referencing Trump and Prince Andrew
Meghan Markle’s Possible UK Return Sparks Renewed Attention on Sussex Role
Starmer Convenes Urgent Talks on Cost-of-Living Pressures Linked to Iran Conflict
Starmer Convenes Urgent Talks on Cost-of-Living Pressures Linked to Iran Conflict
UK Investors Eye Bargain Shares Ahead of ISA Deadline Amid Market Volatility
UK Investors Eye Bargain Shares Ahead of ISA Deadline Amid Market Volatility
Northern Lights Expected Over UK Skies Tonight Amid Strong Solar Activity
UK Condemns Iran Missile Strike and Warns Against Threats to British Personnel
UK Warns of Global Flight Disruptions as Iran Conflict Escalates Under Trump’s Leadership
UK Condemns Iran After Missile Strike Targets Strategic Diego Garcia Base
Deadly Meningitis Outbreak in UK Reinforces Urgency of Vaccination Campaigns
Iran Launches Long-Range Missile Strike on Remote US-UK Base, Signaling Expanded Reach
Iran Launches Long-Range Missile Strike on Remote US-UK Base, Signaling Expanded Reach
UK Rules Out Cyprus Base Role in Joint US Self-Defence Framework
UK Ends Hereditary Peerage Rights in Parliament in Historic Constitutional Reform
Lord Walney Warns of Expanding Iranian Influence Networks Within the United Kingdom
Iranian National Among Two Arrested After Attempt to Access UK Nuclear Submarine Base
Deregulation, Artificial Intelligence, and Fraud Laws Reshape UK Financial Services Landscape
UK Considers Lower Speed Limits to Reduce Fuel Use Amid Escalating Energy Crisis
UK Borrowing Costs Surge to Post-Crisis High as Markets React to Inflation and War Risks
UK Government Prepares Emergency Economic Measures as Iran Conflict Fuels Financial Risks
Meningitis B Outbreak in the UK Raises Urgent Health Warnings as Cases Surge
Iran Issues Stark Warning to Britain Over US Base Access Amid Expanding Conflict
United Kingdom Authorizes US Strikes from British Bases as Iran Threatens Key Shipping Routes
Reform UK Suspends Scottish Candidate Following Financial Misconduct Allegations
Apple issues an unusual warning: this is how your iPhone can be hacked without you doing anything
UK and Nigeria Reach Agreement to Accelerate Return of Irregular Migrants
UK Sets New Aid Priorities Following Significant Budget Reductions
Cyprus President Urges Open Dialogue Over Future of British Sovereign Base Areas
×