Spanish engineer Sammy Azdoufal was developing an app to control the Romo using a PS5 gamepad, and
while integrating with the DJI service, he reportedly discovered by accident that his own in-development app was being recognized as an authorized client not just for his own vacuum but for thousands of
other devices as well.
.
.
.
DJI acknowledged the backend authorization validation issue and
stated that through two updates (a first patch on February 8, 2026, and a second update on February 10, 2026),
the fix was automatically rolled out to all service nodes
Source: DJI Romo robovac bug reportedly exposed thousands of live home feeds
▶ Original source: https://www.guru3d.com/story/dji-romo-robovac-bug-reportedly-exposed-thousands-of-live-home-feeds/