Independent cyber security expert who goes by the pseudonym Boschko Found The Chinese humanoid robot Unitree G1 has two vulnerabilities that allow it to execute code remotely from nearby devices via Bluetooth Low Energy (BLE) without prior pairing and authentication.
Image source: unitree.com
The research project, called UniBLEed, shows that due to this attack, the Locomotion PC installed on the robot (the computer responsible for its main functions) can be compromised. The identification codes of these vulnerabilities are CVE-2026-76639 and CVE-2026-76640. The second is part of a series of exploits related to Bluetooth.
Unitree G1 implements Bluetooth in a way that it can accept some commands from nearby devices without pairing and authentication. In order to fully interact with the bot, a unique AES-128 encryption key is required, but anyone with a company account can obtain it through the Unitree Cloud API – just know the serial number of a specific bot.
Using this feature, the researchers forced the Unitree G1 to connect to its Wi-Fi hotspot and then exploited a buffer overflow vulnerability in the Bluetooth service running as root. As a result, he was able to execute arbitrary commands with maximum privileges.
The CVE-2026-76639 vulnerability also allows remote code execution, but in a different way. The chat_go artificial intelligence service discovered a path traversal vulnerability when uploading files to the knowledge base. Using this, the researchers uploaded files to the directory of the bashrunner utility, which determines which applications are allowed to run, again ensuring that the command was executed with root privileges. In addition, this vulnerability can obtain the information required to carry out attacks using CVE-2026-76640.
The dangers of these two vulnerabilities are not limited to the ability to intercept bot control – an attacker gained control of a Locomotion PC. This computer runs Linux and runs services on it that function as the root control machine, such as the engine, camera, audio and voice functions.
What makes UniBLEed particularly dangerous is its ability to automatically propagate attacks. According to the researchers, once the Unitree G1 is compromised, the malware could theoretically use it to attack another robot within Bluetooth range and then further repeat the process without human intervention. After gaining root privileges on the Locomotion PC, the attacker can access the robot’s critical systems. In addition, researchers found keys and other secret information used to access third-party cloud services on the computer. Therefore, vulnerabilities not only bring the threat of data leakage or remote monitoring, but also the potential risk of infected robots engaging in dangerous behaviors.
The vulnerabilities were reproduced on four copies of the Unitree G1, and the manufacturer paid the researchers a $5,000 reward. The patch released largely corrects the reported issues. Bot owners are advised to install Unitree updates, limit Bluetooth connections, check account security and consider possible vulnerabilities in the system until the issue is confirmed to be fully resolved.
If you find an error, select it with your mouse and press CTRL+ENTER.










