Urgent.News

What's breaking now, across thousands of outlets.

Tech

Flock cameras are riddled with security vulnerabilities and hard-coded credentials

This morning, DDoSecrets released a dataset containing filesystem images from an active Flock ALPR (Automatic License Plate Recognition) camera. The investigative joint effort published by 404 Media and Wired delved into the information provided. The hackers behind stegan0gram explained their motivation: to reveal the secrets behind Flock cameras that monitor public spaces. They dismantled the hardware, examined the solar power components, and reverse engineered the cameras.

The Flock cameras operate on a customized version of Android. Specifically, the version installed on this camera was built on June 5, 2025, but it was running Android 8.1, a version that was released in 2017 and officially stopped receiving support from Google in 2021. The Android patch level was also outdated, being at 2018-06-05, which means the camera had not received security updates for the past eight years.

On the Linux kernel level, this camera was running Linux 3.18.71, which was last maintained in May 2019. This kernel is nine years behind the current version. Several known vulnerabilities are likely affecting the camera's components, as the patch level predates the availability of these fixes.

A Flock spokesperson said in response to 404 Media and Wired: "Security is a priority for us, and we have a public Vulnerability Disclosure Policy for researchers. However, we did not receive any report through this process. Therefore, we lack sufficient information to assess the claims being made." They encouraged any legitimate vulnerabilities to be reported through their official channel.

The Flock camera features 20 separate apps, with 19 of them sharing a library called com.flocksafety.android.common.lib. Inside this library, there is a hardcoded API key in the CameraSettings class. This API key allows hackers to use a camera's MAC address to obtain the camera's credentials from the Flock backend service at hpnotiq.flocksafety.com.

These credentials are then stored in plaintext on the camera. The API key is stored in the system partition, which can be downloaded and extracted from partitions/24_system.img. Once extracted, the file build.prop reveals the Android version and patch level.

The Linux version can be found in the boot partition, accessible by extracting partitions/21_boot.img. The MAC address associated with this camera is F4:6A:DD:57:46:FB. The API key can be used to acquire bearer tokens, which can then be utilized to interact with Flock's backend servers, allowing unauthorized access as if it were the camera itself.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at micahflee.com →

More in Tech

More from Thursday 17 September →