London Daily

Focus on the big picture.
Friday, Dec 26, 2025

Amazon Alexa security bug allowed access to voice history

Amazon Alexa security bug allowed access to voice history

A flaw in Amazon's Alexa smart home devices could have allowed hackers access personal information and conversation history, cyber-security researchers say.

Attackers could install or remove apps on a device without the owner knowing, Check Point Research reports.

The hack "required just one click on an Amazon link" purposely crafted by the attacker, it says.

The firm told Amazon about the flaw, which has now been fixed.

Amazon said: "The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us."

It said it did not know of any case where a bad actor had used the vulnerability to target its customers.

In January, Amazon said there were "hundreds of millions" of Alexa devices in the world.

Malicious skills


Check Point said the hack required the creation of a malicious Amazon link, which would be sent to an unsuspecting user.

Once they clicked the link, the attacker could get a list of all installed Alexa "skills" - or apps - and steal a token allowing them add or remove skills.

One way to use the flaw would be to remove a skill and then install a malicious one that uses the same "invocation phrase" - the series of spoken words used to trigger it. This could have been done without the user knowing.

The next time the user tried to activate that skill, it would have run the attacker's app instead.

The attackers would have been able to see Alexa's voice history - a record of conversations between the user and device.

Check Point said this could create major problems, pointing to banking skills that let the user check their account balance.

"This could lead to exposure of personal information, such as banking data history," they argued - even though it does not save banking login details.

Amazon objected to this suggestion, however, saying that banking information - like balances - was redacted in the record of Alexa's responses, so it could not have been accessed.

The attack would also allow access to personal information in the Amazon profile, such as a home address, Check Point said.

Amazon also said it believed the use of a secret malicious skill was less likely than Check Point's researchers implied.



Amazon’s head of Alexa Dave Limp on privacy concerns



It said there were systems in place to prevent malicious skills from ever hitting the Alexa Skills Store - and that security reviews were part of their process.

Badly behaving apps were also routinely deactivated, it said.

"Their screening process probably would have caught most bad actors - they are quite good at that and know their reputation is at stake," said University of Surrey cyber-security expert Prof Alan Woodward.

"The thing about this hack was that it was due to a vulnerability that is well-known… so it's surprising to see it in Amazon's estate."

He said the access to voice records was a big concern, but was unsure if other hackers could have known about the vulnerabilities in specific subdomains used to launch the attack.

"Although if the security researchers found it, I'm sure less scrupulous people could have done the same."

Newsletter

Related Articles

0:00
0:00
Close
Princesses Beatrice and Eugenie Join Royal Family at Sandringham Christmas Service
Fine Wine Investors Find Little Cheer in Third Year of Falls
UK Mortgage Rates Edge Lower as Bank of England Base Rate Cut Filters Through Lending Market
U.S. Supermarket Gives Customers Free Groceries for Christmas After Computer Glitch
Air India ‘Finds’ a Plane That Vanished 13 Years Ago
Caviar and Foie Gras? China Is Becoming a Luxury Food Powerhouse
Hong Kong Climbs to Second Globally in 2025 Tourism Rankings Behind Bangkok
From Sunniest Year on Record to Terror Plots and Sports Triumphs: The UK’s Defining Stories of 2025
Greta Thunberg Released on Bail After Arrest at London Pro-Palestinian Demonstration
Banksy Unveils New Winter Mural in London Amid Festive Season Excitement
UK Households Face Rising Financial Strain as Tax Increases Bite and Growth Loses Momentum
UK Government Approves Universal Studios Theme Park in Bedford Poised to Rival Disneyland Paris
UK Gambling Shares Slide as Traders Respond to Steep Tax Rises and Sector Uncertainty
Starmer and Trump Coordinate on Ukraine Peace Efforts in Latest Diplomatic Call
The Pilot Barricaded Himself in the Cockpit and Refused to Take Off: "We Are Not Leaving Until I Receive My Salary"
UK Fashion Label LK Bennett Pursues Accelerated Sale Amid Financial Struggles
U.S. Government Warns UK Over Free Speech in Pro-Life Campaigner Prosecution
Newly Released Files Shed Light on Jeffrey Epstein’s Extensive Links to the United Kingdom
Prince William and Prince George Volunteer Together at UK Homelessness Charity
UK Police Arrest Protesters Chanting ‘Globalise the Intifada’ as Authorities Recalibrate Free Speech Enforcement
Scambodia: The World Owes Thailand’s Military a Profound Debt of Gratitude
Women in Partial Nudity — and Bill Clinton in a Dress and Heels: The Images Revealed in the “Epstein Files”
US Envoy Witkoff to Convene Security Advisers from Ukraine, UK, France and Germany in Miami as Peace Efforts Intensify
UK Retailers Report Sharp Pre-Christmas Sales Decline and Weak Outlook, CBI Survey Shows
UK Government Rejects Use of Frozen Russian Assets to Fund Aid for Ukraine
UK Financial Conduct Authority Opens Formal Investigation into WH Smith After Accounting Errors
UK Issues Final Ultimatum to Roman Abramovich Over £2.5bn Chelsea Sale Funds for Ukraine
Rare Pink Fog Sweeps Across Parts of the UK as Met Office Warns of Poor Visibility
UK Police Pledge ‘More Assertive’ Enforcement to Tackle Antisemitism at Protests
UK Police Warn They Will Arrest Protesters Chanting ‘Globalise the Intifada’
Trump Files $10 Billion Defamation Lawsuit Against BBC as Broadcaster Pledges Legal Defence
UK Says U.S. Tech Deal Talks Still Active Despite Washington’s Suspension of Prosperity Pact
UK Mortgage Rules to Give Greater Flexibility to Borrowers With Irregular Incomes
UK Treasury Moves to Position Britain as Leading Global Hub for Crypto Firms
U.S. Freezes £31 Billion Tech Prosperity Deal With Britain Amid Trade Dispute
Prince Harry and Meghan’s Potential UK Return Gains New Momentum Amid Security Review and Royal Dialogue
Zelensky Opens High-Stakes Peace Talks in Berlin with Trump Envoy and European Leaders
Historical Reflections on Press Freedom Emerge Amid Debate Over Trump’s Media Policies
UK Boosts Protection for Jewish Communities After Sydney Hanukkah Attack
UK Government Declines to Comment After ICC Prosecutor Alleges Britain Threatened to Defund Court Over Israel Arrest Warrant
Apple Shutters All Retail Stores in the United Kingdom Under New National COVID-19 Lockdown
US–UK Technology Partnership Strains as Key Trade Disagreements Emerge
UK Police Confirm No Further Action Over Allegation That Andrew Asked Bodyguard to Investigate Virginia Giuffre
Giuffre Family Expresses Deep Disappointment as UK Police Decline New Inquiry Into Andrew Mountbatten-Windsor Claims
Transatlantic Trade Ambitions Hit a Snag as UK–US Deal Faces Emerging Challenges
Ex-ICC Prosecutor Alleges UK Threatened to Withdraw Funding Over Netanyahu Arrest Warrant Bid
UK Disciplinary Tribunal Clears Carter-Ruck Lawyer of Misconduct in OneCoin Case
‘Pink Ladies’ Emerge as Prominent Face of UK Anti-Immigration Protests
Nigel Farage Says Reform UK Has Become Britain’s Largest Party as Labour Membership Falls Sharply
Google DeepMind and UK Government Launch First Automated AI Lab to Accelerate Scientific Discovery
×