Hack One Robot, Reach the Next: Unitree G1 Security Flaws
Brief
A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby.
Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable.
In his technical write-up , he details two vulnerabilities, CVE-2026-76639 and CVE-2026-76640, that can be chained across Bluetooth, Unitree’s cloud infrastructure, the mobile app, and the robot’s firmware to gain unauthenticated root access to any G1 within Bluetooth range.
The first bug lives entirely inside the robot itself, no wireless attack surface needed if you can reach it over Ethernet.
