Security flaws in children's smartwatches expose millions to surveillance risks

Research at DEF CON 34 reveals that millions of children’s smartwatches across various brands share security weaknesses, risking live location tracking, message interception, and unauthorised camera activation due to shared software architectures and inadequate protection.

Children’s smartwatches are increasingly sold as everyday essentials, combining location tracking, messaging and a measure of independence for families that want to keep in touch with younger children. Yet a security disclosure highlighted at DEF CON 34 suggests that many low-cost devices in this category are far less protected than parents may assume. Researchers said they were able to reach live location data, alter GPS information, read messages, listen to audio captured by the watch and, in some cases, activate the camera without any obvious warning to the child wearing the device. According to the reporting from 36Kr and corroborating coverage from Notebookcheck, the problem is not limited to a handful of products but appears to affect millions of watches sold under many different brand names.

The most concerning detail is that the weakness appears to sit in the software supply chain rather than in a single model. Researchers said they did not need to buy and dismantle dozens of watches to uncover the issue; instead, they analysed companion apps for different brands and found that many were built from the same underlying code and connected to a shared server. Notebookcheck reported that apps tied to 39 brands and about 46 models were linked to a common vendor structure, which means one flaw can potentially expose a large number of products at once. In practical terms, a device that looks like a distinct brand may, under the bonnet, be little more than a re-skinned version of the same platform.

That shared architecture also helps explain why these problems are so hard to fix. Once the software stack is centralised with a third-party vendor, the individual watch brands often have little direct control over security updates, server-side protections or long-term maintenance. 36Kr noted previous cases in which companies responded to exposed flaws by burying menu options deeper in the interface rather than replacing the underlying credentials or design weakness. Other vendors have publicly acknowledged vulnerabilities after internal reviews, but researchers have argued that such disclosures have not always been followed by meaningful patching. The result is a product category in which the cheapest models can become effectively stranded once they are in the market.

The broader lesson is that low price can mask a very thin security model. Wired has previously reported that even after years of warnings, many children’s smartwatches still permit tracking or eavesdropping because of weak security practices and shared platforms. The new findings at DEF CON 34 reinforce that concern and add an uncomfortable twist: devices marketed as tools for safety may themselves become instruments for surveillance if their software is not properly isolated, updated and tested. For parents, the appeal of a bargain is obvious, but the technical trade-off can be severe when the same flaw scales across many brands at once.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.