A Unitree G1 can be rooted over Bluetooth by anyone nearby

Unitree / product pagePress kit
Security researcher Olivier Laflamme published two vulnerability chains against the Unitree G1 EDU humanoid on 27 August 2026, filed as CVE-2026-76639 and CVE-2026-76640.
The first is a path traversal in the robot’s chat service: an uploaded knowledge file with traversal characters in its name writes arbitrary content into the directory a second service reads from, and restarting that service executes it as root.
The second matters more. It chains five bugs, beginning with a Bluetooth Low Energy characteristic that accepts writes without pairing. From there an attacker retrieves the robot’s AES key in plaintext, uses a cloud endpoint that decrypted keys without checking who owned the robot, injects a command into the Wi-Fi provisioning routine to move the machine onto a network it controls, and finishes with a 1,050-byte buffer overflow that calls system as root. No credentials are needed and no pairing takes place. Laflamme describes the chain as wormable: a compromised robot can carry it to other G1 units in Bluetooth range.
Unitree validated both, paid a combined $6,700 bounty on 6 August, and patched the cloud ownership check in July. No fixed firmware for the Bluetooth overflow was confirmed at publication.