An adversary can create a new, malicious skill that is specifically built to open when the user says certain phrases. Those phrases are designed to be similar, if not nearly identical, to phrases used to open legitimate apps. So, the device would hear the approximate phrase and may open the rogue app instead of the legitimate one, thus hijacking the connection.
https://threatpost.com/voice-squatting-turns-alexa-google-home-into-silent-spies/132068/
No comments:
Post a Comment