Wyze apparently hid a major flaw in its security cameras for three years

Wyze Cam mounted on a tree
Wyze security camera (Image credit: Wyze)

What you need to know

  • Wyze's security camera line was susceptible to hacking for years.
  • The company knew about the major security flaw, but it didn't tell customers.
  • Wyze only ended support for some of the affected cameras since it couldn't roll out a fix due to hardware limitations.

If you're still using a Wyze Cam v1 right now, it's probably a good idea to stop using the security camera immediately. It appears that a major vulnerability allowed intruders to access your stored videos or watch you in secret, and Wyze didn't inform customers in the three years since it first learned about the security flaw.

Bitdefender has revealed that it discovered a vulnerability in Wyze's Cam security camera line in March 2019 and notified the company about it (via The Verge). However, Wyze failed to respond until November 2020.

"While looking into the Wyze Cam device, we identified several vulnerabilities that let an outside attacker access the camera feed or execute malicious code to further compromise the device," Bitdefender said.

Wyze said in a blog post that the scope of the flaw is limited since a hacker would first need to gain access to your home Wi-Fi before they can view the camera's stored videos.

"We first would like to let our users know that these vulnerabilities required some form of local network access," Wyze explained. "So, you would have had to expose your local network to either the bad actor directly or the Internet at large for these vulnerabilities to be exploitable remotely."

Fortunately for owners of Wyze's best indoor security cameras, including the Cam v2 and v3, a patch was released in late January, as per Bleeping Computer. But this also means the company was slow in taking steps to fix the flaw. For the past three years, Wyze's Cam v1, v2, and v3 cameras have been susceptible to hackers.

However, the Cam v1 was left out in the cold, with Wyze simply ending support for it in February since that particular model "couldn’t support the necessary security updates" due to its limited memory. While the issue has been patched for newer models, Wyze never informed customers about the nature of the security flaw, keeping them in the dark.

"Bitdefender and Wyze both take the safety of affected users seriously," Wyze said in its blog. "Knowing that we were actively working on risk mitigation and corrective updates, we came to the conclusion together that it was safest to be prudent about the details until the vulnerabilities were fixed."

It's unclear whether the flaw was exploited, but it would have given intruders access to the contents of your camera's SD card.

The Verge also raised questions about Bitdefender's late disclosure. Its PR director, Steve Fiore, told the news outlet that "disclosing the findings before having the vendor provide patches would have put a lot people at risk."

However, it's not typical for security researchers to wait three years before disclosing vulnerabilities.

Jay Bonggolto
News Writer & Reviewer

Jay Bonggolto always keeps a nose for news. He has been writing about consumer tech and apps for as long as he can remember, and he has used a variety of Android phones since falling in love with Jelly Bean. Send him a direct message via Twitter or LinkedIn.

Read more
The Galaxy S24 Plus with a light behind it
Samsung’s most secure feature seems to have a few holes
A statue of the multicolored "G" in Google on the Google campus in Mountain View
Google warns Android users of a zero-day software exploit causing instability
Arlo Pro 5S 2K Camera lifestyle render
Best security cameras with local storage 2025
Top-down view of Google Pixel 9 Pro and 9 Pro XL
Another Pixel 9 Pro camera bar fault hints at a possible design flaw
Pushing doorbell on Ring Video Doorbell 3 promo image
Best smart video doorbells that store locally (not in the cloud) 2025
Chromecast 3rd Gen plugged into back of television
Google finally rolls out fix for 'Untrusted Device' errors on older Chromecasts
Latest in Smart Home
TerraMaster F8 SSD Plus internals next to external casing
The best all-flash Plex NAS finally gets a great discount — act now!
Using the Google Home Max.
Google Home Max will soon lose support for a critical safety feature
Tailscale install screen NAS
I used Tailscale to block ads on my phone while traveling, and it was amazing
Samsung T7 SSDs next to laptop
Need more storage? Samsung's portable T7 SSD is nearly 50% OFF during Amazon's Presidents' Day sale
TerraMaster F4-424 Max NAS review
TerraMaster F4-424 Max review: This 10GbE 4-bay Plex NAS destroys the DiskStation DS923+
UGREEN DXP2800 2-bay NAS server review
UGREEN DXP2800 review: One of the best 2-bay NAS servers you can buy today
Latest in News
The promotional image for Google Workspace feature drops.
The March Workspace feature drop upgrades Gemini's note-taking and translation tools
The Samsung Galaxy S25 Edge on display
New leak shows off Samsung Galaxy S25 Edge in 'Titanium' variants
YouTube Music home screen
YouTube Music's personalized radio stations are getting even smarter
The back of the Obsidian Google Pixel 9 Pro
Some Pixel owners had a delayed start, thanks to alarm clock failures
Samsung Galaxy S25 Ultra Home Screen - 16x9
Heads up — Samsung's detailed One UI 7 rollout schedule for Galaxy appears
Screenshots showing the new Garmin Connect Plus subscription in action on mobile phones above the text "Connect+"
Garmin Connect+ subscription adds Active Intelligence, new workouts and coaching