A fresh security review at Black Hat reveals that 39 parental control and child-tracking apps are sending data to a server in China, with 45 vulnerabilities that could enable live audio, camera feeds, and sensitive information to be accessed by malicious actors.
A new security review presented at Black Hat has cast fresh doubt on some of the most widely used parental control and child-tracking apps. According to researchers Vangelis Stykas, chief technology officer at Kumio, and Felipe Solferini, a principal AI security engineer, 39 consumer brands that appeared to be separate products were all sending data to the same server in China. The pair also identified 45 vulnerabilities that could, in the wrong hands, allow access to live audio, camera feeds and backend systems holding sensitive information.
The findings underline a broader problem with child-monitoring software: these tools are designed to collect highly sensitive data in order to work. Many request broad permissions, including GPS tracking, screen recording and access to the microphone and camera. That makes them useful for parents trying to keep track of younger children, but it also turns them into attractive targets for criminals if security controls are weak or absent.
Stykas and Solferini said they were able to demonstrate an attack with minimal effort, using only a free account on one of the services. In one case, they showed that a children’s smartwatch could be made to place a call and stream live audio without displaying any obvious sign that a call was in progress. They also said they found evidence suggesting the weakness may have been present for as long as two years. Despite sending more than 30 emails to the manufacturers, they said they received no direct response.
The Black Hat disclosure fits into a wider pattern of concern about the child-tracking market. Cybernews previously reported that 10 popular Android monitoring apps, with more than 85 million combined downloads, contained security flaws including third-party trackers and weak SSL certificate handling, which could expose data to interception. The US Federal Trade Commission has also warned that parental control products can leak names, phone numbers and email addresses if they are poorly secured. For parents, the practical takeaway is simple: built-in tools from Apple, Google and Microsoft are generally a safer starting point than third-party apps that demand deep access to a child’s device.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





