- Yarbo’s smart robotic lawn mowers have a critical security vulnerability that allows remote hijacking.
- The breach exposed user data, including GPS coordinates, Wi-Fi passwords, and email addresses, across 12,000 units globally.
- Independent researchers confirmed security flaws in Yarbo’s Gen 2 and Gen 3 models, including unencrypted Bluetooth communication.
- The vulnerabilities allowed hackers to pair with the mower within 30 meters and gain full control in under 90 seconds.
- Yarbo has issued a mandatory firmware update and initiated a partial recall to address the security issues.
Yarbo, a Shenzhen-based manufacturer of smart robotic lawn mowers, has acknowledged critical security vulnerabilities after a widely publicized incident in which a hacker remotely took control of a device and ran it over its owner. The breach exposed sensitive user data—including GPS coordinates, Wi-Fi passwords, and email addresses—across an estimated 12,000 units globally. In response, Yarbo has issued a mandatory firmware update, initiated a partial recall, and pledged to overhaul its cybersecurity protocols, signaling a turning point for IoT device safety in consumer robotics.
Security Flaws Confirmed by Independent Researchers
Independent cybersecurity researchers at the Netherlands-based firm Secura uncovered the vulnerabilities in Yarbo’s Gen 2 and Gen 3 models, revealing that the devices used unencrypted Bluetooth communication and exposed API endpoints accessible without authentication. Testing showed that a hacker within 30 meters could pair with the mower in under 90 seconds, gaining full control over navigation, blade activation, and access to stored network credentials. Further analysis by BBC News confirmed that user accounts linked to the Yarbo app were protected by only a single layer of password authentication, with no two-factor verification. These flaws enabled attackers to track users’ home locations and potentially exploit network access for broader intrusions into home IoT ecosystems.
Yarbo, Hackers, and the Rise of IoT Exploitation
Yarbo, launched in 2020 as a subsidiary of agricultural tech firm Yuandao, positioned its robotic mowers as premium smart devices with advanced GPS mapping and app-based controls. However, the company’s rapid expansion into European and North American markets—bolstered by crowdfunding campaigns and online retail—outpaced its investment in cybersecurity infrastructure. The hacker responsible for the high-profile incident, who later disclosed their identity to Reuters under the alias ‘LawnMowerGhost’, claimed they accessed the device using publicly available tools and a GitHub repository detailing Yarbo’s API structure. Meanwhile, consumer advocacy groups have criticized Chinese IoT manufacturers for lax regulatory oversight, noting that devices like Yarbo are often certified under minimal cybersecurity standards before export.
Trade-Offs Between Innovation and User Safety
The Yarbo incident underscores the growing tension between consumer convenience and digital security in the $3.8 billion robotic lawn mower market. While these devices offer automation and energy efficiency, their integration into home networks introduces significant attack surfaces. Disabling Bluetooth or isolating the mower on a separate Wi-Fi network mitigates risk but undermines core functionality. Yarbo’s proposed fix—mandatory firmware updates with end-to-end encryption and two-factor authentication—comes at the cost of user experience, particularly for older models with limited processing power. Moreover, only 37% of affected users had installed the patch within the first 72 hours of its release, according to internal Yarbo data, highlighting the challenge of securing devices post-deployment.
Why the Timing of the Recall Matters Now
The recall follows a surge in IoT-related incidents during the 2024 spring season, as homeowners reactivate stored devices after winter. This timing amplifies risk, as outdated firmware remains unpatched for months. The incident also coincides with the European Union’s upcoming Cyber Resilience Act, set to take effect in 2025, which will mandate strict security requirements for all connected devices sold in the bloc. Yarbo’s proactive response may be partly strategic, aiming to avoid heavier penalties and reputational damage. Internal documents suggest the company first became aware of the vulnerability in late 2023 but delayed action due to concerns over production delays and customer backlash.
Where We Go From Here
In the next six to twelve months, three scenarios could unfold. First, widespread adoption of the patch could stabilize the fleet, with Yarbo regaining consumer trust through transparency and third-party audits. Second, continued low update rates may lead to secondary attacks, prompting regulatory intervention from bodies like the U.S. Federal Trade Commission or Germany’s BSI. Third, the incident could catalyze industry-wide reforms, with competitors like Husqvarna and Robomow accelerating their own security roadmaps. Regardless of outcome, the Yarbo case will likely serve as a cautionary benchmark in IoT product development.
Bottom line — the Yarbo hack reveals a systemic flaw in the Internet of Things ecosystem: convenience has long overshadowed security, and until regulations enforce accountability, consumers will remain vulnerable to preventable digital and physical threats.
Source: The Verge




