Yarbo Pledges Robot Mower Fixes, Keeps Backdoor

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Yarbo issued a 1,200-word public response on May 8, 2026, confirming the core findings of researcher Andreas Makris's May 7 vulnerability report, apologizing, and laying out a multi-phase remediation plan for its robot lawn mowers.
- Yarbo has already temporarily disabled its remote diagnostic tunnels, reset device root passwords that were shared across the entire fleet, and closed unauthenticated status-query endpoints to block further exploitation.
- Yarbo committed to per-device independent credentials, dynamically derived passwords (no longer hardcoded in firmware), and a user-authorized, allowlist-based remote diagnostic model with audit logging — with the first wave of OTA security updates expected within one week.
- Yarbo is not removing its remote backdoor entirely; the tunnel will remain available to "authorized internal company personnel" after user authorization, despite the company having previously claimed remote access was already restricted to authorized employees — a claim the original report disproved.
- Security researcher Andreas Makris confirmed Yarbo has opened direct communication, established a dedicated security response center, and told him fixes are their highest priority, though he has not yet been able to verify whether access is still possible after the changes.
- Yarbo is pushing a mandatory security firmware update to all devices that requires an internet connection to apply; the company says users can keep devices offline without voiding warranty or service coverage.
- Yarbo attributes the vulnerabilities to "historical" or "legacy" design choices and claims some reported issues "do not apply to currently shipped products," but has not disclosed what percentage of its fleet runs on legacy versus current services.
Why it matters: Yarbo customers buying a connected, blade-equipped robot are now weighing whether to apply a mandatory firmware update or keep devices offline to avoid the very remote-access channel the company refuses to fully remove. The pledge stops short of the cleanest fix — eliminating the persistent backdoor — and Yarbo's own co-founder admits the company previously misrepresented how restricted that access was, which means security-conscious buyers have to take the "historical issues" framing on faith until Makris can independently verify the patch.
Ask SkimNews




