PSA: Multiple Critical HMD Fuse /
#HarmBlock+ Vulnerabilities
Over the past seven months, I've responsibly disclosed multiple critical security vulnerabilities affecting the HMD Fuse and HarmBlock+ platform to HMD and Xplora. Those reports have now resulted in the platform being taken offline.
During my research, I was able to:
• Silently pair with any HMD Fuse device, anywhere in the world, assume the role of the parent/guardian, access the child's live GPS location, remotely manage installed apps, and disable all HarmBlock+ protections.
• Emulate any HMD Fuse device, allowing arbitrary device data to be uploaded and presented to the parent/guardian application.
• Remove all HarmBlock+ protections entirely by factory resetting the device using Google's Find My Device or a standard ADB command, despite the platform being marketed as "deeply embedded into the OS" and "cannot be bypassed or uninstalled."
HMD has notified the UK Information Commissioner's Office (
@ICOnews). However, affected users have not been informed of the nature or impact of the incident. Instead, the app simply states the service is unavailable due to "maintenance and security upgrades."
Based on my findings, these vulnerabilities were present from the product's launch and affected the platform's core security model. In my opinion, they created a significant risk to children's privacy and safety and render the product unfit for its intended purpose.
Whilst I commend HMD for taking the platform offline, I believe parents deserve a clear explanation of what happened, what information may have been affected, and what steps they should take.
A detailed analysis is coming soon.
Clarification:
The HMD Fuse embeds HarmBlock AI, developed by
@SafeToNet. Despite the similar names, HarmBlock AI and HarmBlock+ are different products. The vulnerabilities I've disclosed relate to HMD's HarmBlock+ implementation and surrounding platform, not SafeToNet's HarmBlock AI technology. These findings do not indicate any weakness in HarmBlock AI itself.