- Sources: primary, coverage, discussion
- Summary: Micah Lee unpacked a camera image from a dataset published by a collective that took units out of the field, naming the partitions and files he read, and reports a security patch level roughly eight years old on an Android build whose fixes stopped in 2021, plus a backend API key hardcoded into a shared library that is bundled into all 19 Flock applications on that image. He writes that this key can presumably be used to obtain credentials for any Flock camera from its MAC address, which is his inference from one imaged unit rather than a tested result, and he names CVE-2021-1905, a Qualcomm Adreno GPU use-after-free patched in May 2021, and CVE-2018-9568, the WrongZone kernel socket type confusion patched in December 2018, as bugs the camera is probably vulnerable to, stating he did not test either against a device and did not use the extracted credentials. Flock says it received no report through its disclosure process and cannot assess the claims.
- Why it matters: A fleet device running an OS build that stopped receiving fixes in 2021 has no cheap recovery path, and if the author's expectation about the hardcoded key holds beyond the one imaged unit, rotating that credential means reaching every deployed camera.
- Follow-up: Track whether Flock rotates the hardcoded key, ships an OS update to deployed units, confirms either named CVE against hardware, or states whether the key differs between units.
send feedback on this story