Researchers disclosed UniBLEed, two critical attack chains that can grant root-level remote code execution on Unitree G1 humanoid robots. CVE-2026-76639 affects G1 EDU firmware through version 1.5.2: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a world-readable AES-128 key, and path traversal in the chat_go knowledge-upload API allow an attacker to restart the bashrunner service, place a malicious script in its execution path, and have it run as root on the locomotion PC.
CVE-2026-76640 reportedly permits an attacker within Bluetooth Low Energy range to write to an unpaired BLE characteristic, recover the robot's AES-128 key through an improperly authorized Unitree cloud decryption endpoint, alter Wi-Fi settings, and exploit a buffer overflow in btgatt-server for root command execution. The BLE route may be wormable, allowing a compromised robot to target nearby G1 units. Unitree validated the findings, added an account-to-robot ownership binding check to the cloud key-recovery process in July 2026, and said patches were available or under development for the reported issues.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-76639 record for unauthenticated root RCE in Unitree G1 EDU firmware through version 1.5.2 was received by disclosure@vulncheck.com.
Unitree paid a total $5,000 bounty: $1,000 for the chat_go RCE and $4,000 for the BLE RCE.
Unitree reportedly validated the CVE-2026-76640 chain, which combines unauthorized BLE access, cloud key recovery, Wi-Fi provisioning abuse, and a btgatt-server overflow to obtain root execution.
Unitree reportedly validated the CVE-2026-76639 chat_go and bashrunner root-RCE chain affecting Unitree G1 robots.
Unitree implemented an ownership-binding check for its cloud key-recovery endpoint, preventing authenticated accounts from decrypting bootstrap material for robots they did not own.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecvefeed.io
Open sourceboschko.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.