Security flaws in cheap children's GPS watches expose privacy risks

Security researchers reveal widespread vulnerabilities in affordable children’s GPS watches and trackers, risking location privacy and enabling unauthorised access beyond initial safety concerns.

A cheap GPS watch or tracker for a child may look like a practical compromise, but security researchers say the real trade-off can be privacy. A recent Wired report, based on work presented at the Black Hat cybersecurity conference, found that dozens of children’s watches and car accessories shared the same backend systems, leaving many devices open to account takeover, location tracking and, in some cases, remote access to features such as the camera and emergency contact settings.

The underlying problem is not limited to one product line. CBS News reported that several children’s GPS watches were shown to have serious weaknesses that could let outsiders follow a child’s whereabouts or contact them without a parent’s knowledge. Earlier testing by consumer and security researchers has pointed to similar flaws in a range of devices, including weak authentication, exposed data and app security that is far below what parents might reasonably expect.

The risks go beyond watches. Avast researchers previously found that about 600,000 child trackers sold under different brand names had serious vulnerabilities, including insecure mobile apps, default passwords and weaknesses that could allow outsiders to spoof a child’s location or listen through a microphone. TechCrunch has also reported on GPS trackers that could be reached remotely by SMS, exposing live location data and enabling microphone activation without consent.

Consumer advocates have warned for years that this category of gadget often shares the same hidden technology across many brands. TechCrunch reported in 2017 that an EU consumer watchdog flagged basic security and privacy failures in several children’s smartwatches. The pattern matters: if many products are built from the same software stack or supply chain, one flaw can affect a wide range of devices sold through major retailers.

That is why the safest advice is often to buy from established companies with a record of fixing security problems, even if the price is higher. Tom’s Guide suggests checking independent reviews, securing home Wi-Fi with a strong password and current firmware, and avoiding purchases based solely on retail-site ratings. For parents who want a tracker, larger brands such as Apple, Fitbit and Garmin may cost more, but they are more likely to offer support, updates and a route for security reporting than an obscure no-name label.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.