Unitree G1 EDU robot flaws enable root RCE via Bluetooth

Two root RCE chains (CVE-2026-76639, CVE-2026-76640) affect the Unitree G1 EDU, including a Bluetooth Low Energy path to root on the Locomotion PC. No verified fixed firmware release exists; Unitree patched the cloud ownership check in July 2026.
Featured · Olivier Laflamme
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Nvidia-backed Lambda raises $1B debt for chip deal
- Developer fatigue with AI-generated specs and plans
- Meta researchers train 8B model to match Claude Opus 4.5
- Decathlon scales demand forecasting with Chronos-2 on AWS
- Salesforce achieves Multi-AZ HA with SageMaker Inference Components