London Daily

Focus on the big picture.
Tuesday, Feb 17, 2026

Amazon Alexa security bug allowed access to voice history

Amazon Alexa security bug allowed access to voice history

A flaw in Amazon's Alexa smart home devices could have allowed hackers access personal information and conversation history, cyber-security researchers say.

Attackers could install or remove apps on a device without the owner knowing, Check Point Research reports.

The hack "required just one click on an Amazon link" purposely crafted by the attacker, it says.

The firm told Amazon about the flaw, which has now been fixed.

Amazon said: "The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us."

It said it did not know of any case where a bad actor had used the vulnerability to target its customers.

In January, Amazon said there were "hundreds of millions" of Alexa devices in the world.

Malicious skills


Check Point said the hack required the creation of a malicious Amazon link, which would be sent to an unsuspecting user.

Once they clicked the link, the attacker could get a list of all installed Alexa "skills" - or apps - and steal a token allowing them add or remove skills.

One way to use the flaw would be to remove a skill and then install a malicious one that uses the same "invocation phrase" - the series of spoken words used to trigger it. This could have been done without the user knowing.

The next time the user tried to activate that skill, it would have run the attacker's app instead.

The attackers would have been able to see Alexa's voice history - a record of conversations between the user and device.

Check Point said this could create major problems, pointing to banking skills that let the user check their account balance.

"This could lead to exposure of personal information, such as banking data history," they argued - even though it does not save banking login details.

Amazon objected to this suggestion, however, saying that banking information - like balances - was redacted in the record of Alexa's responses, so it could not have been accessed.

The attack would also allow access to personal information in the Amazon profile, such as a home address, Check Point said.

Amazon also said it believed the use of a secret malicious skill was less likely than Check Point's researchers implied.



Amazon’s head of Alexa Dave Limp on privacy concerns



It said there were systems in place to prevent malicious skills from ever hitting the Alexa Skills Store - and that security reviews were part of their process.

Badly behaving apps were also routinely deactivated, it said.

"Their screening process probably would have caught most bad actors - they are quite good at that and know their reputation is at stake," said University of Surrey cyber-security expert Prof Alan Woodward.

"The thing about this hack was that it was due to a vulnerability that is well-known… so it's surprising to see it in Amazon's estate."

He said the access to voice records was a big concern, but was unsure if other hackers could have known about the vulnerabilities in specific subdomains used to launch the attack.

"Although if the security researchers found it, I'm sure less scrupulous people could have done the same."

Newsletter

Related Articles

0:00
0:00
Close
UK Markets Signal Opportunity as Starmer Confronts Intensifying Political Pressure
Trump Criticises Newsom’s UK Climate Pact, Defends Federal Authority Over Foreign Engagements
UK’s Top Prosecutor Says ‘No One Is Above the Law’ as Police Review Claims Against Ex-Prince Andrew
Businessman Adam Brooks weighs in on the reports that the US is set to help Hamit Coskun flee the UK, over free speech concerns
U.S. Attorney General Pam Bondi Releases 3.5 Million Pages of Jeffrey Epstein Case Files
US Secretary of State Marco Rubio Comment on European allies report blaming Russia for killing late Kremlin critic Alexei Navalny using toxin from poison dart frogs
Eighty-Year-Old Lottery Winner Sentenced to 16.5 Years for Drug Trafficking
UK Quran Burner May Receive Asylum in the US Amid Legal Challenges
Rubio Calls for Sweeping U.N. Reform, Saying It Has Failed to End Wars in Gaza and Ukraine
10,000 Condoms Distributed at Winter Olympics 2026 Athlete Village Depleted Within 72 Hours
Poland's President Advocates for Evaluating Independent Nuclear Weapons Development
Prince William Meets Saudi Crown Prince as Epstein-Andrew Fallout Casts Shadow
Starmer Calls for Renewed ‘Hard Power’ Investment at European Security Summit
UK Police Establish National Taskforce to Handle Domestic Epstein-Linked Allegations
UK Court Rules Ban on Palestine Action Unlawful in Major Free Speech Test
UK Faces Prospect of Net Migration Turning Negative as Economic Impact Looms
Mayor of Serdobsk in Russia’s Penza Region Resigns After Housing Certificates Granted to Migrant Family Trigger Public Outcry
Pentagon Reviews Anthropic Partnership After Claude AI Reportedly Used in Operation Targeting Nicolás Maduro
President Donald Trump and Hip-Hop’s Political Realignment: Pardons, Public Endorsements, and the Struggle Over Cultural Influence
China’s EV Makers Face Mandatory Return to Physical Buttons and Door Handles in Driver-Distraction Safety Overhaul
Goldman Sachs and DP World Executive Resignations: Elite-Reputation Risk and Corporate Governance Fallout From the Epstein Disclosures
‘Amelia’: The UK Government’s Anti-Extremism Game Villain Who Became a Protest Symbol
Peter Mandelson Asked to Testify Before US Congress Over Jeffrey Epstein Links
Walmart's Earnings and UK Economic Data Highlight Upcoming Financial Trends
UK Green Party Considering Proposal to Legalize Heroin for an Inclusive Society
SpaceX's New Vision: Lunar City Takes Precedence Over Mars Colonization
OpenAI and DeepCent Superintelligence Race: Artificial General Intelligence and AI Agents as a National Security Arms Race
Document Suggests Prince Andrew Shared UK Briefing on Afghan Investment Opportunities with Jeffrey Epstein
We will protect them from the digital Wild West.’ Another country will ban social media for under-16s
McDonald's Shortens Breakfast Hours in Australia Due to Egg Shortage
Heineken announces cut of 6,000 jobs due to declining beer demand
Beijing Brands UK Hong Kong Visa Expansion ‘Despicable and Reprehensible’ After Jimmy Lai Sentencing
Tesco Chief Warns UK Is ‘Sleepwalking’ Toward a Joblessness Crisis
Trump’s ‘Act of Great Stupidity’ Comment on UK Chagos Deal Reverberates Through Diplomacy and Strategy
New U.S. filings say Jeffrey Epstein repaid Les Wexner one hundred million dollars after theft allegation
Commerce Secretary Howard Lutnick acknowledges 2012 visit to Jeffrey Epstein’s private island as lawmakers scrutinise past ties
Helsing and Stark Defence loitering-munition drones and Germany’s race to industrialise battlefield autonomy
UK orders deletion of Courtsdesk court-data archive, reigniting the fight over who controls public justice records
UK Police Review Fresh Claims Involving Prince Andrew as Senior Royals Respond to Epstein Files
Keir Starmer’s Premiership Faces Unprecedented Strain as Epstein Fallout Deepens
Starmer Vows to Stay in Office as UK Government Faces Turmoil After Epstein Fallout
China and UK Signal Tentative Reset with Commitment to Steadier, Professionally Managed Relations
UK Confirms Imminent Increase in ETA Fee to £20 as Entry Rules Tighten
UK Signals Possible Seizure of Russia-Linked ‘Shadow Fleet’ Tanker in Escalation of Sanctions Enforcement
Epstein Scandal Piles Unprecedented Pressure on UK Prime Minister Keir Starmer’s Leadership
UK’s ‘Most Romantic Village’ Celebrates Valentine’s Day and Explores the Festival’s Rich History
The Implications of Expanding Voting Rights to Non-EU Foreign Residents in France
Ghislaine Maxwell to Testify Before US Congress on February 9
Al.com Acquired by Crypto.com Founder for $70 Million
Apple iPhone Lockdown Mode blocks FBI data access in journalist device seizure
×