Recent investigations by cybersecurity experts have highlighted significant flaws in Sonos smart speakers that could be exploited by malicious individuals to secretly listen in on conversations.
The vulnerabilities have resulted in a major breach of Sonos’s secure boot process across numerous devices, enabling remote attackers to compromise several units wirelessly, according to NCC Group’s security analysts Alex Plaskett and Robert Herrera.
Exploiting these weaknesses could allow a remote attacker to covertly capture audio from Sonos devices through an over-the-air assault. These issues affect all versions released before Sonos S2 version 15.9 and Sonos S1 version 11.12, which were released in October and November 2023.
The details of these security issues were unveiled at Black Hat USA 2024. The vulnerabilities are:
- CVE-2023-50809: This flaw in the Sonos One Gen 2’s Wi-Fi stack involves improper validation of an element during the WPA2 handshake, potentially leading to remote code execution.
- CVE-2023-50810: This issue pertains to the U-Boot component in the Sonos Era-100 firmware, allowing for persistent arbitrary code execution with Linux kernel privileges.
NCC Group, which analyzed the boot process to enable remote code execution on Sonos Era-100 and Sonos One devices, identified CVE-2023-50809 as a result of a memory corruption vulnerability in the Sonos One’s wireless driver, which uses a third-party MediaTek chipset. MediaTek noted that this driver vulnerability could lead to a local privilege escalation without needing additional execution rights or user interaction.
This initial breach allows attackers to follow up with actions such as gaining full control over the device, followed by deploying a novel Rust-based implant to capture audio from the microphone when the speaker is in close proximity.
CVE-2023-50810, on the other hand, involves a series of vulnerabilities in the secure boot process of Era-100 devices, allowing unauthorized code execution at the kernel level. This flaw can be exploited alongside an existing privilege escalation vulnerability to execute code at the ARM EL3 level and extract cryptographic secrets secured by hardware.
The researchers emphasized two key takeaways from their findings: Firstly, OEM components must meet the same security standards as in-house parts, and secondly, vendors should thoroughly model threats and validate all remote attack vectors of their products.
In light of these secure boot issues, it is crucial to rigorously test the boot chain to prevent the introduction of such weaknesses. Both hardware and software attack vectors should be considered during testing.
The revelation comes amid another critical finding by firmware security firm Binarly, which disclosed that hundreds of UEFI products from various vendors are vulnerable to a serious firmware supply chain issue known as PKfail. This flaw allows attackers to bypass Secure Boot protections and install malware, as many products are using a test Platform Key from American Megatrends International (AMI), which was intended to be replaced with a secure key by downstream entities.



