Flock ALPR cameras: aged Android/Linux build plus hard-coded API key to mint device credentials
Micah Lee (16 September 2026; dataset from DDoSecrets / stegan0gram field extraction, also covered by 404 Media and Wired) analyses firmware from an in-use Flock Safety automatic licence-plate reader (ALPR) camera. The unit ran a modified Android 8.1 build dated 5 June 2025 on Linux 3.18.71 — far past vendor/Google support — and ships multiple Flock apps. Lee documents a hard-coded x-api-key in an app used to request device credentials from hpnotiq.flocksafety.com (MAC-address keyed), with returned credentials stored in plaintext and usable to mint bearer tokens via device-login.flocksafety.com. Lee lists older public Android/kernel CVEs the patch level likely predates but does not claim live exploitation tests on this hardware. Flock gave a statement to 404 Media/Wired (per Lee). No CVE assigned in the write-up. Primary: Micah Lee analysis; context: DDoSecrets dataset.
- Product
- Flock Safety ALPR / surveillance cameras (Android-based firmware)
- Versions
- Analysed image: Android 8.1 build 2025-06-05; Linux 3.18.71 (one field unit)
- Exploited in Australia?
- unknown
- Patch to
- Operators of Flock (or similar) ALPR estates: demand current supported OS/firmware, rotate any exposed device API keys/credentials, restrict camera management planes; do not reuse leaked keys from public research
Primary: Micah Lee — Flock cameras hard-coded credentials (16 Sep 2026) · 404 Media — Flock camera software / ALPR dataset context (with Wired)
