The mobile application accompanying the watch has unencrypted communications with its backend server and the server enables unauthenticated access to data. As a consequence, the data such as location history, phone numbers, the serial number can easily be retrieved and changed.

A malicious user can send commands to any watch making it call another number of his choosing, can communicate with the child wearing the device or locate the child through GPS.

The product does not comply with the Radio Equipment Directive.

Originating Piece here

Measures ordered by public authorities (to: Distributor): Recall of the product from end users

Description:  Smartwatch for children in a cardboard box 12x15x8cm. the product was sold online.

Country of origin: Germany

Alert submitted by: Iceland

#Alert #Safety #GDPR #Children #EU #Smartwatch #Privacy #Tracking #Security