HomeArticle

The children's watches bought for kids may be leaking their whereabouts.

三易生活2026-09-28 09:57
For products where vulnerabilities have already been discovered, discontinuing their use is the best choice.

For today's children, kids' smartwatches are no longer just practical gadgets, but also essential items for them to fit into their peers' social circles.

For parents, what they value most is undoubtedly the positioning and communication functions of kids' smartwatches. However, well-known top-tier brands usually sell their kids' smartwatches at a high price, while there are many more affordable alternatives on the market. So why not take the seemingly good bargain? After all, they all look pretty much the same.

Recently, a high-profile security conference revealed the reason why these kids' smartwatches are so cheap: they are fundamentally unsafe, and can even be used to silently track, monitor, and eavesdrop on your children without their knowledge.

Unbranded kids' smartwatches have zero security level at all

Researchers demonstrated their findings at DEF CON 34, the world's largest cybersecurity conference. In their related research, the researchers easily took control of millions of kids' smartwatches.

After hacking into these kids' smartwatches, the researchers found that they could access the real-time location of the devices, forge non-existent GPS data, intercept text messages and voice information, even silently listen to the sound captured by the watch, or use the camera on the watch to take photos. None of these behaviors will leave any noticeable prompts on the kids' smartwatches.

It's pretty terrifying, right? Then the question arises: how did these researchers discover such severe security vulnerabilities? It has to be said that this is the most bizarre part of the whole incident.

Did they crack the devices? Actually the problem lies in the supply chain

According to common sense, to discover and exploit a security vulnerability in a device, you should at least buy one first and then conduct relevant research on it.

But in this extremely serious kids' smartwatch security incident, the relevant researchers did not even need to buy all these kids' smartwatches. They only downloaded several apps for kids' smartwatches of different brands, and then noticed the hidden trick behind them.

This is exactly where the problem lies. The researchers found that the apps for about 46 models of kids' smartwatches from 39 different brands actually come from the same software vendor, and all of them share one single server.

What does that mean? They gave an example that the mobile apps used by these different brands of kids' smartwatches are essentially just a set of codes with a reskinned interface, or even simply a renamed version. This means that once a vulnerability is found in one of the apps, the security protection mechanisms of dozens of kids' smartwatches from different brands are all cracked at the same time.

Worse still, these security vulnerabilities can hardly be fixed

After noticing this incident, we at 3eLife also looked up previously exposed cases related to security vulnerabilities of kids' smartwatches, and found that their "post-incident disposal" is almost universally unsolvable.

For example, after a certain brand was exposed that all its product lines shared the same underlying security key, the only solution they took was to hide the entry to the device's "engineering mode" deeper, without changing the problematic key at all.

Another example is that another brand released an announcement admitting that they found several security vulnerabilities during their "self-audit". But security researchers pointed out that there are actually dozens of vulnerabilities (far more than "several") in the related products, and the vendor only acknowledged the existence of the vulnerabilities, without taking any patching actions afterwards.

Why is that? To put it bluntly, since these brands do not develop their own software, and their data is not stored on their own servers at all. This means that the repair of their security vulnerabilities can only passively wait for the upstream vendor to update the software. If the upstream vendor chooses to play dead, even if these brands "want to make good products", they can actually do nothing about it.

Besides, the product strategy of these brands relies mainly on low cost, so even if the upstream vendor provides new software codes, it is unrealistic to expect the new codes to be updated to the old products that have already been sold.

This means that for the approximately 26 million kids' smartwatches that have been found to have "built-in security vulnerabilities", they have basically no security at all now.

This article is from the WeChat Official Account "3eLife" (ID: IT-3eLife), written by San Yijun, and authorized for release by 36Kr.