Unsecured web portal puts kids' chats with AI toy at risk of being accessed by anyone, including Gmail users.
A security vulnerability discovered in the Bondu chat portal allows any user with a valid Google account to access conversations between children and the AI-powered dinosaur toys.
Researchers Joseph Thacker and Joel Margolis stumbled upon this while investigating reports about the toy's AI safety features. They found that Bondu's web console exposed over 50,000 chat transcripts of child users who had never manually deleted them.
According to Bondu CEO Fateen Anam Rafid, security fixes were implemented within hours after the discovery was made, followed by a broader review and implementation of additional measures for all users.
However, critics warn that this incident highlights larger concerns regarding AI-powered toys for children. Margolis expressed that having access to sensitive data such as conversations about children's thoughts and feelings can be exploited in horrific ways, including child abuse or manipulation.
Researchers also suspect that some AI-enabled toy companies may use generative AI programming tools to create products with security flaws. Bondu declined to comment on whether their console was programmed with such tools.
The incident has sparked concerns among parents regarding the safety and security of these toys, which can collect a vast amount of personal data from children.
A security vulnerability discovered in the Bondu chat portal allows any user with a valid Google account to access conversations between children and the AI-powered dinosaur toys.
Researchers Joseph Thacker and Joel Margolis stumbled upon this while investigating reports about the toy's AI safety features. They found that Bondu's web console exposed over 50,000 chat transcripts of child users who had never manually deleted them.
According to Bondu CEO Fateen Anam Rafid, security fixes were implemented within hours after the discovery was made, followed by a broader review and implementation of additional measures for all users.
However, critics warn that this incident highlights larger concerns regarding AI-powered toys for children. Margolis expressed that having access to sensitive data such as conversations about children's thoughts and feelings can be exploited in horrific ways, including child abuse or manipulation.
Researchers also suspect that some AI-enabled toy companies may use generative AI programming tools to create products with security flaws. Bondu declined to comment on whether their console was programmed with such tools.
The incident has sparked concerns among parents regarding the safety and security of these toys, which can collect a vast amount of personal data from children.