Beautiful Virgin Islands

Monday, Dec 22, 2025

Amazon Alexa security bug allowed access to voice history

Amazon Alexa security bug allowed access to voice history

A flaw in Amazon's Alexa smart home devices could have allowed hackers access personal information and conversation history, cyber-security researchers say.

Attackers could install or remove apps on a device without the owner knowing, Check Point Research reports.

The hack "required just one click on an Amazon link" purposely crafted by the attacker, it says.

The firm told Amazon about the flaw, which has now been fixed.

Amazon said: "The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us."

It said it did not know of any case where a bad actor had used the vulnerability to target its customers.

In January, Amazon said there were "hundreds of millions" of Alexa devices in the world.

Malicious skills


Check Point said the hack required the creation of a malicious Amazon link, which would be sent to an unsuspecting user.

Once they clicked the link, the attacker could get a list of all installed Alexa "skills" - or apps - and steal a token allowing them add or remove skills.

One way to use the flaw would be to remove a skill and then install a malicious one that uses the same "invocation phrase" - the series of spoken words used to trigger it. This could have been done without the user knowing.

The next time the user tried to activate that skill, it would have run the attacker's app instead.

The attackers would have been able to see Alexa's voice history - a record of conversations between the user and device.

Check Point said this could create major problems, pointing to banking skills that let the user check their account balance.

"This could lead to exposure of personal information, such as banking data history," they argued - even though it does not save banking login details.

Amazon objected to this suggestion, however, saying that banking information - like balances - was redacted in the record of Alexa's responses, so it could not have been accessed.

The attack would also allow access to personal information in the Amazon profile, such as a home address, Check Point said.

Amazon also said it believed the use of a secret malicious skill was less likely than Check Point's researchers implied.



Amazon’s head of Alexa Dave Limp on privacy concerns



It said there were systems in place to prevent malicious skills from ever hitting the Alexa Skills Store - and that security reviews were part of their process.

Badly behaving apps were also routinely deactivated, it said.

"Their screening process probably would have caught most bad actors - they are quite good at that and know their reputation is at stake," said University of Surrey cyber-security expert Prof Alan Woodward.

"The thing about this hack was that it was due to a vulnerability that is well-known… so it's surprising to see it in Amazon's estate."

He said the access to voice records was a big concern, but was unsure if other hackers could have known about the vulnerabilities in specific subdomains used to launch the attack.

"Although if the security researchers found it, I'm sure less scrupulous people could have done the same."

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
UK Fashion Label LK Bennett Pursues Accelerated Sale Amid Financial Struggles
U.S. Government Warns UK Over Free Speech in Pro-Life Campaigner Prosecution
Newly Released Files Shed Light on Jeffrey Epstein’s Extensive Links to the United Kingdom
Prince William and Prince George Volunteer Together at UK Homelessness Charity
UK Police Arrest Protesters Chanting ‘Globalise the Intifada’ as Authorities Recalibrate Free Speech Enforcement
Scambodia: The World Owes Thailand’s Military a Profound Debt of Gratitude
Women in Partial Nudity — and Bill Clinton in a Dress and Heels: The Images Revealed in the “Epstein Files”
US Envoy Witkoff to Convene Security Advisers from Ukraine, UK, France and Germany in Miami as Peace Efforts Intensify
UK Retailers Report Sharp Pre-Christmas Sales Decline and Weak Outlook, CBI Survey Shows
UK Government Rejects Use of Frozen Russian Assets to Fund Aid for Ukraine
UK Financial Conduct Authority Opens Formal Investigation into WH Smith After Accounting Errors
UK Issues Final Ultimatum to Roman Abramovich Over £2.5bn Chelsea Sale Funds for Ukraine
Rare Pink Fog Sweeps Across Parts of the UK as Met Office Warns of Poor Visibility
UK Police Pledge ‘More Assertive’ Enforcement to Tackle Antisemitism at Protests
UK Police Warn They Will Arrest Protesters Chanting ‘Globalise the Intifada’
Trump Files $10 Billion Defamation Lawsuit Against BBC as Broadcaster Pledges Legal Defence
UK Says U.S. Tech Deal Talks Still Active Despite Washington’s Suspension of Prosperity Pact
UK Mortgage Rules to Give Greater Flexibility to Borrowers With Irregular Incomes
UK Treasury Moves to Position Britain as Leading Global Hub for Crypto Firms
U.S. Freezes £31 Billion Tech Prosperity Deal With Britain Amid Trade Dispute
Prince Harry and Meghan’s Potential UK Return Gains New Momentum Amid Security Review and Royal Dialogue
Zelensky Opens High-Stakes Peace Talks in Berlin with Trump Envoy and European Leaders
Historical Reflections on Press Freedom Emerge Amid Debate Over Trump’s Media Policies
UK Boosts Protection for Jewish Communities After Sydney Hanukkah Attack
UK Government Declines to Comment After ICC Prosecutor Alleges Britain Threatened to Defund Court Over Israel Arrest Warrant
Apple Shutters All Retail Stores in the United Kingdom Under New National COVID-19 Lockdown
US–UK Technology Partnership Strains as Key Trade Disagreements Emerge
UK Police Confirm No Further Action Over Allegation That Andrew Asked Bodyguard to Investigate Virginia Giuffre
Giuffre Family Expresses Deep Disappointment as UK Police Decline New Inquiry Into Andrew Mountbatten-Windsor Claims
Transatlantic Trade Ambitions Hit a Snag as UK–US Deal Faces Emerging Challenges
Ex-ICC Prosecutor Alleges UK Threatened to Withdraw Funding Over Netanyahu Arrest Warrant Bid
UK Disciplinary Tribunal Clears Carter-Ruck Lawyer of Misconduct in OneCoin Case
‘Pink Ladies’ Emerge as Prominent Face of UK Anti-Immigration Protests
Nigel Farage Says Reform UK Has Become Britain’s Largest Party as Labour Membership Falls Sharply
Google DeepMind and UK Government Launch First Automated AI Lab to Accelerate Scientific Discovery
UK Economy Falters Ahead of Budget as Growth Contracts and Confidence Wanes
Australia Approves Increased Foreign Stake in Strategic Defence Shipbuilder
Former UK Prime Minister Boris Johnson proclaims, “For Ukraine, surrendering their land would be a nightmare.”
Microsoft Challenges £2.1 Billion UK Cloud Licensing Lawsuit at Competition Tribunal
Fake Doctor in Uttar Pradesh Accused of Killing Woman After Performing YouTube-Based Surgery
Hackers Are Hiding Malware in Open-Source Tools and IDE Extensions
Traveling to USA? Homeland Security moving toward requiring foreign travelers to share social media history
UK Officials Push Back at Trump Saying European Leaders ‘Talk Too Much’ About Ukraine
UK Warns of Escalating Cyber Assault Linked to Putin’s State-Backed Operations
UK Consumer Spending Falters in November as Households Hold Back Ahead of Budget
UK Orders Fresh Review of Prince Harry’s Security Status After Formal Request
U.S. Authorises Nvidia to Sell H200 AI Chips to China Under Security Controls
Trump in Direct Assault: European Leaders Are Weak, Immigration a Disaster. Russia Is Strong and Big — and Will Win
"App recommendation" or disguised advertisement? ChatGPT Premium users are furious
"The Great Filtering": Australia Blocks Hundreds of Thousands of Minors From Social Networks
×