Affected Systems
Unitree G1 EDU humanoid robot. Firmware versions not definitively confirmed; researcher tested V1.5.2. G1 (non-EDU) and other Unitree robot models have unconfirmed applicability. Both vulnerabilities grant root access on the Locomotion PC.
Exploitation Status
Proof-of-concept demonstrated by researcher Olivier Laflamme. CVE-2026-76639 exploits path traversal in chat_go to reach bashrunner for root RCE. CVE-2026-76640 chains unpaired BLE write, cloud key recovery (now patched), and Wi-Fi provisioning buffer overflow for root RCE. Cloud authorization flaw patched July 2026; BLE chain PoC flow broken. No evidence of active exploitation in the wild.
Business Impact
Organizations deploying Unitree G1 EDU robots face risk of complete device compromise via network-adjacent or Bluetooth proximity attacks. Root access enables arbitrary code execution, potential lateral movement, data exfiltration, and physical manipulation of robot behavior. No confirmed firmware fix available as of disclosure (August 27, 2026). Cloud authorization patch mitigates one attack vector but does not address underlying vulnerabilities. Risk elevated in environments where robots operate near untrusted networks or physical proximity to attackers.
Urgency
🟠Within 24 hours
Recommended Actions
- Isolate Unitree G1 EDU robots on dedicated network segments with strict firewall rules blocking chat_go and bashrunner service ports from untrusted sources
- Disable Bluetooth Low Energy on G1 EDU robots if operational requirements permit; monitor BLE activity logs for unauthorized pairing or provisioning attempts
- Contact Unitree support to confirm patched firmware version and upgrade timeline; verify cloud account ownership validation is active for all registered robots
- Implement network monitoring to detect path-traversal attempts targeting chat_go and unusual bashrunner execution patterns on Locomotion PC
- Restrict physical access to areas where G1 EDU robots operate to prevent BLE proximity attacks; consider RF shielding for high-security deployments
