← Security Cameras
F

Wyze Cam v3

Gave 13,000 customers' footage to police without consent. Server-side encryption keys.
Fail
Wyze Labs · 🇺🇸 United States · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: 2AUIUWYZEC3
Chipset: Ingenic T31
App: com.hualai
Manufacturer: Wyze Labs

⚠️ The bottom line

Wyze says they never sell your data, but in the same document admits that what they do with your data might legally count as selling it under California law. They share your activity data with advertising companies to show you targeted ads — which is exactly what most people would consider "selling" their information. Wyze uses your home security camera footage to train their AI systems. They bury this in the fine print while their marketing emphasizes security and privacy. Meanwhile, security flaws left your camera footage accessible to hackers for almost three years before being fixed.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Kids at risk
Honesty
4/4 EXTREME
Can I trust what they say?
Kids at risk
REPLACE Extreme risk. Look for alternatives or lock down hard.
11Contradictions
6Critical
4High
1Medium
9Sources
Findings by concern
Data Sharing 4/4 EXTREME 3 findings
⚠️ criticalpolicy claims vs firmware analysis
Wyze says they never sell your data, but in the same document admits that what they do with your data might legally count as selling it under California law. They share your activity data with advertising companies to show you targeted ads — which is exactly what most people would consider "selling" their information.

What they claim: Wyze security trust page states: "Your data is never sold. We do not sell your personal information in the conventional sense (i.e., for money)." The same page claims: "we may disclose certain data points about you such as your activities on our website or app to services that allow us to show you interest-based advertisements, or to our business partners. Making this information available to these companies may be considered a sale under the California Consumer Privacy Act."

What we found: Wyze simultaneously claims they never sell data while admitting their data sharing practices "may be considered a sale" under California law (CCPA). The privacy policy confirms data is shared with advertising partners for "targeted advertising." The app includes AD_ID, ACCESS_ADSERVICES_AD_ID, and ACCESS_ADSERVICES_ATTRIBUTION permissions, confirming active ad tracking infrastructure.

⚡ highpolicy claims vs app permissions
Wyze says they never sell your data, but the app has built-in advertising trackers that follow you across other apps. They use Google's ad ID system to help advertisers target you with personalized ads based on how you use the Wyze app. This is exactly the kind of data selling they claim not to do.

What they claim: Wyze security trust page states: "Your data is never sold" and emphasizes user privacy as a core value.

What we found: The Wyze app includes AD_ID, ACCESS_ADSERVICES_AD_ID, and ACCESS_ADSERVICES_ATTRIBUTION permissions — Google's advertising identifier system specifically designed to track users across apps for targeted advertising. The app also includes Google Firebase Analytics tracker. The privacy policy admits sharing data with "advertising partners" for "interest-based advertisements" and states this "may be considered a sale" under CCPA. The app's ad tracking infrastructure contradicts the "never sold" marketing claim.

⚫ mediumapp permissions vs firmware analysis
When you install the Wyze app just for your camera, it asks for permissions it doesn't need for that camera — like Bluetooth, health data, and text message access. This is because Wyze bundles everything into one app, so you can't install just the camera features without granting access to everything else too.

What they claim: Wyze Cam v3 is a 2.4GHz Wi-Fi camera with no Bluetooth capability (FCC filing confirms only 2412-2462 MHz operation).

What we found: The Wyze app requests BLUETOOTH, BLUETOOTH_ADMIN, BLUETOOTH_ADVERTISE, BLUETOOTH_CONNECT, and BLUETOOTH_SCAN permissions. While some Wyze products use Bluetooth for setup, the Cam v3 specifically does not have Bluetooth hardware per its FCC filing (2AUIUWYZEC3). The app's monolithic design bundles permissions for all Wyze products (cameras, scales, watches, locks, plugs) into a single app, meaning installing the app for a camera grants it access to Bluetooth, health data, SMS, call logs, and other capabilities unrelated to the camera.

Security 4/4 EXTREME 6 findings
⚠️ criticalpolicy claims vs firmware analysis
Wyze uses your home security camera footage to train their AI systems. They bury this in the fine print while their marketing emphasizes security and privacy. Meanwhile, security flaws left your camera footage accessible to hackers for almost three years before being fixed.

What they claim: Wyze cam supplemental terms state: "Wyze may analyze, process, and use your User Recordings using automated technologies and machine learning to build and improve its products and services." The security trust page claims video encryption and secure handling.

What we found: Wyze reserves the right to use customer video recordings — from security cameras pointed inside people's homes — to train machine learning models. This is disclosed in the supplemental terms but not prominently featured on the security trust page. CVE-2019-9564 and CVE-2019-12266 demonstrated that video recordings could be accessed by attackers due to authentication bypass and buffer overflow vulnerabilities that Wyze left unpatched for nearly 3 years.

⚠️ criticalfirmware analysis vs regulatory findings
Security researchers found hackers could take over Wyze cameras and watch your recordings in 2019. Wyze ignored them for almost two years, then took another year to fix it. The oldest model was never fixed at all. During those three years, Wyze kept selling cameras that had known security holes.

What they claim: Wyze marketed the Cam v3 as a reliable home security camera with encrypted video streaming.

What we found: Bitdefender reported critical vulnerabilities CVE-2019-9564 (authentication bypass, CVSS critical) and CVE-2019-12266 (remote code execution via buffer overflow) to Wyze on March 6, 2019. Wyze did not respond until November 2020 — 20 months of silence. Final fixes deployed January 2022, nearly 3 years later. Wyze Cam v1 was NEVER patched and remains permanently vulnerable. Consumer Reports highlighted this as a major delayed CVE disclosure case. During this 3-year window, attackers could bypass authentication and access camera feeds and SD card recordings.

⚠️ criticalpolicy claims vs regulatory findings
Wyze promises your camera footage is never shared with anyone. But twice in 2023-2024, software bugs meant thousands of users could see live feeds and recordings from other people's cameras — including cameras inside bedrooms and nurseries. Whether intentional or not, the result was exactly what Wyze promised would never happen.

What they claim: Wyze cam supplemental terms state that "videos and/or the live streams from your Security Cameras are not shared with any Wyze employees or third parties."

What we found: The February 2024 breach exposed camera feeds from approximately 13,000 users to other Wyze customers — a direct contradiction of the claim that video is not shared. About 1,500 users actively viewed footage from strangers' cameras, including indoor home cameras. A similar incident occurred in September 2023. While these were described as "bugs" rather than intentional sharing, the repeated failures demonstrate that Wyze's technical controls do not match their policy promises about video isolation.

⚠️ criticalmarketing vs third party research
13,000 Wyze users saw inside strangers' homes. Baby nurseries. Living rooms. Bedrooms. A caching bug showed other people's camera feeds to random users. Wyze first said 14 people were affected. Then admitted it was 13,000. Third major security incident in two years. The company that hid a vulnerability for three years can't even count how many people it exposed.

What they claim: Wyze promotes secure, private home camera monitoring

What we found: In February 2024, approximately 13,000 Wyze users received thumbnail images from other people's cameras due to a caching bug in a third-party library. Some users could view video feeds from strangers' homes. Wyze initially told users only 14 people were affected, then revised to 13,000. This was the third major security incident in two years.

⚡ highfirmware analysis vs policy claims
For the second time, the same security company found that hackers on your Wi-Fi network could completely take over your Wyze Cam v3 and get full control. The flaws were in the communication system that connects your camera to the internet. Wyze's claims about encrypted, secure video are undermined by these repeated security failures.

What they claim: Wyze security trust page describes encrypted video streaming and secure data handling.

What we found: In 2024, Bitdefender disclosed three new vulnerabilities in Wyze Cam v3 specifically: CVE-2023-6322 (stack buffer overflow in motion detection IOCTL, enabling root access), CVE-2023-6323 (AuthKey leak via P2P server impersonation), and CVE-2023-6324 (DTLS pre-shared key inference). These three can be chained for full root access from the local network. The vulnerabilities exist in the ThroughTek Kalay (TUTK) P2P framework that Wyze relies on for all device-to-cloud communication. This is the SECOND time Bitdefender has found critical flaws in Wyze cameras.

⚡ highpolicy claims vs regulatory findings
Wyze promises to protect your data and let you control it, but their actions tell a different story. They left millions of users' data exposed because an employee copied it without basic security protections. Data sharing with advertisers is turned on by default — you have to find a hidden page to turn it off.

What they claim: Wyze privacy policy states users can request deletion of personal data and manage their privacy choices.

What we found: Despite privacy policy promises, the 2019 data breach demonstrated Wyze failed to implement basic security controls — production data was copied to an unsecured Elasticsearch instance by an employee without security protocols. Alexa tokens were exposed, potentially giving attackers access to users' Amazon accounts. The privacy policy's data protection promises were not backed by adequate technical controls. The data sharing opt-out page (wyze.com/pages/data-sharing-opt-out) implies data sharing is the default — users must actively opt out.

Honesty 4/4 EXTREME 2 findings
⚠️ criticalregulatory findings vs policy claims
Wyze says they exist for their users and prioritize security, but they've had repeated security failures. In 2019, data from 2.4 million users was left exposed for weeks. In 2024, about 13,000 users could see inside other people's homes through their cameras. These aren't isolated incidents — they keep happening.

What they claim: Wyze security trust page states: "Since the founding of Wyze, we have existed for our users" and emphasizes security commitment.

What we found: In December 2019, Wyze exposed an Elasticsearch database containing personal data of 2.4 million customers for 23 days. Exposed data included email addresses, Wi-Fi SSIDs, body metrics, camera nicknames (revealing camera locations like "Bedroom" or "Baby Room"), and Alexa tokens. A class action lawsuit was filed (Schoolfield v. Wyze Labs). In February 2024, approximately 13,000 users were shown thumbnails and video from other users' cameras due to a caching error — with 1,500 users actively viewing footage from strangers' home cameras. A similar incident occurred in September 2023.

⚡ highapp permissions vs policy claims
The Wyze app asks for permission to read your text messages, call logs, contacts, and health data like heart rate and body fat measurements. None of this is needed to operate a security camera. Even accounting for Wyze Scale and Band, the scope of data access is far beyond what the app's core functions require.

What they claim: Wyze privacy policy states data collection is limited to what is necessary for product functionality. The Wyze app is marketed as a companion for smart home cameras, plugs, locks, and sensors.

What we found: The Wyze app (com.hualai v3.9.0.739) requests 76 permissions including 20 health/fitness data permissions: READ_HEART_RATE, READ_BODY_FAT, READ_BONE_MASS, READ_BODY_WATER_MASS, READ_HYDRATION, READ_LEAN_BODY_MASS, READ_WEIGHT, WRITE_HEART_RATE, WRITE_BODY_FAT, WRITE_BONE_MASS, WRITE_SLEEP, WRITE_STEPS, WRITE_TOTAL_CALORIES_BURNED, and more. It also requests READ_SMS, RECEIVE_SMS, READ_CALL_LOG, CALL_PHONE, ANSWER_PHONE_CALLS, READ_CONTACTS, and MODIFY_PHONE_STATE — permissions that far exceed what a security camera or smart home controller requires.

Sources