Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Delve accused of misleading customers with ‘false compliance’

Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

    21 March 2026

    Microsoft is retiring some of the Copilot AI bloat on Windows

    21 March 2026

    The best AI investment may be in energy technology

    20 March 2026

    Bot traffic to overtake human traffic by 2027, says Cloudflare CEO

    20 March 2026

    Multiverse Computing is pushing its compressed AI models into the mainstream

    19 March 2026
  • Apps

    DoorDash Launches New ‘Tasks’ App That Pays Couriers to Submit Videos to Train AI

    21 March 2026

    Google is introducing a new way for users to download Android apps that still protects against fraud

    21 March 2026

    Meta launches new AI content enforcement systems while reducing reliance on third-party vendors

    20 March 2026

    Bluesky Announces $100M Series B After CEO Transition

    20 March 2026

    Amazon is bringing Alexa+ to the UK

    19 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026

    Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

    16 March 2026

    India neobank Fi removes banking services on its platform

    11 March 2026
  • Hardware

    Amazon is working on a new smartphone with Alexa at its core, the report says

    20 March 2026

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026

    MacBook Neo, AirPods Max 2, iPhone 17e and everything else Apple announced this month

    18 March 2026

    Oura enters India’s smart ring market with Ring 4

    17 March 2026

    Apple quietly launches AirPods Max 2

    17 March 2026
  • Media & Entertainment

    Tubi joins forces with popular TikTokers to create original streaming content

    19 March 2026

    Patreon CEO calls AI companies’ fair use argument ‘bogus’, says creators should be paid

    18 March 2026

    Meet Vurt, the first mobile streaming platform for indie filmmakers embracing vertical video

    18 March 2026

    BuzzFeed debuts AI applications for new revenue

    17 March 2026

    Facebook makes it easy for creators to report copycats

    14 March 2026
  • Security

    Delve accused of misleading customers with ‘false compliance’

    21 March 2026

    The US accuses the Iranian government of operating a hacktivist group that hacked the Stryker

    20 March 2026

    CISA Urges Companies to Secure Microsoft Intune Systems After Hackers Mass Wipe Stryker Devices

    20 March 2026

    FBI seizes websites of pro-Iranian hacker group after devastating Stryker attack

    19 March 2026

    FBI is buying location data to track US citizens, director confirms

    19 March 2026
  • Startups

    Microsoft hires Sequoia-backed AI collaboration platform team Cove

    21 March 2026

    Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

    20 March 2026

    Tools for founders to navigate and move past conflicts

    20 March 2026

    Anori, Alphabet’s new X spinout, faces one of the world’s most expensive bureaucratic nightmares

    19 March 2026

    This startup wants to make enterprise software more like a prompt

    19 March 2026
  • Transportation

    Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

    21 March 2026

    Cyberattack on vehicle breathalyzer company leaves drivers stranded in US

    21 March 2026

    Arc expands into electric commercial and defense vessels with $50M raise

    20 March 2026

    Rivian Sacrifices 2027 Profit Target to Push Deeper into Autonomy

    20 March 2026

    K2 will launch its first high-powered computing satellite into space

    19 March 2026
  • Venture

    AI startups are eating up the venture industry, and the returns, so far, are good

    21 March 2026

    Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

    19 March 2026

    AI ‘boys club’ could widen wealth gap for women, says Rana el Kaliouby

    18 March 2026

    Billionaires made a promise – now some want to leave

    17 March 2026

    Antonio Gracias Says He Longs For ‘Pre-Entropic’ Startups – Those Built To Survive Chaos

    17 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Security flaw in a popular smart helmet allowed silent location tracking
Security

Security flaw in a popular smart helmet allowed silent location tracking

techtost.comBy techtost.com8 February 202403 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Security Flaw In A Popular Smart Helmet Allowed Silent Location
Share
Facebook Twitter LinkedIn Pinterest Email

The maker of a popular ski and bike helmet has patched a security flaw that allowed the real-time location of anyone wearing its helmet to be easily tracked.

Livall makes Internet-connected helmets that allow groups of skiers or cyclists to talk to each other using the helmet’s built-in speaker and microphone and share their real-time location with a group of friends using Livall’s smartphone apps.

Ken Munro, founder of UK cyber security testing firm Pen Test Partners, said Livall’s smartphone apps had a simple flaw that allows easy access to any group’s audio chats and location data. Munro says the two apps, one for skiers and one for cyclists, have a total of about a million users.

At the heart of the bug, Munro found that anyone using Livall’s apps for group audio chat and sharing their location must belong to the same friend group, which could be accessed using only that group’s six-digit numeric code.

“That 6-digit team code just isn’t random enough,” Munro said in a blog post describing the flaw. “We could brute force all group IDs in minutes.”

That way, anyone could have access to any of a million possible group chat code permutations.

“Once someone entered a valid group code, they were automatically entered into the group,” Munro said, adding that this happened without notifying the other group members.

“It was therefore trivial to silently join any group, giving us access to any user location and the ability to listen in on any group audio communication,” Munro said. “The only way to detect a rogue group user was if the legitimate user went to check the members of that group.”

Munro and his colleagues in security research are no strangers to finding obscure but often simple flaws in internet-connected products such as car alarms, dating apps and sex toys. The company discovered in 2021 that Peloton was exposing private rider account data due to an API leak, which TechCrunch proudly played the guinea pig for.

After contacting Livall, who requested more information, Munro sent details of the defect on January 7, but received no response and received no confirmation from the company.

Given the risk to users who don’t expect the flaw to be fixed, Munro notified TechCrunch of the flaw, and TechCrunch reached out to Livall for comment.

When contacted via email, Livall founder Bryan Zheng pledged to fix the app within two weeks of our email, but refused to remove Livall apps in the meantime.

TechCrunch withheld this report until Livall confirmed that it had fixed the flaw in app updates released this week.

In an email, Livall R&D director Richard Yi explained that the company improved the randomness of group codes by also adding letters and notifications for new members joining groups. Yi also said that the app now allows disabling shared location at the user level.

allowed cyber security flaw helmet Location popular security silent smart the internet of things tracking
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThea Energy Raises $20M Series A for Pixel-Inspired Fusion Power Plants
Next Article In fact, it’s a good thing for Spotify that Joe Rogan’s podcast is no longer exclusive
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Delve accused of misleading customers with ‘false compliance’

21 March 2026

Cyberattack on vehicle breathalyzer company leaves drivers stranded in US

21 March 2026

The US accuses the Iranian government of operating a hacktivist group that hacked the Stryker

20 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Delve accused of misleading customers with ‘false compliance’

21 March 2026

Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

21 March 2026

New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

21 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026

Nominations for the Startup Battlefield 200 are still open

19 March 2026

Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

17 March 2026
Startups

Microsoft hires Sequoia-backed AI collaboration platform team Cove

Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

Tools for founders to navigate and move past conflicts

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.