Flock Safety map (Intercept 24 Sep / Tom's Hardware 27 Sep): unauth access token → ArcGIS device locations (~300k+); trademark takedown bid
The Intercept (24 September 2026; updated 25 Sep) reports researcher Joshua Michael obtained an access token from Flock Safety without logging in and used it to query ArcGIS (Flock’s geospatial layer) for device locations — a December 2025 snapshot he archived powers a public Flock Surveillance Map covering ~300,000+ devices (ALPR cameras plus acoustic and networking gear). Michael says he disclosed to Flock on 13 November 2025 (non-intrusive unauthenticated endpoints only); Flock acknowledged triage then went quiet. A Doppel complaint on Flock’s behalf alleges trademark infringement and seeks site takedown. Tom's Hardware (27 Sep) amplifies the dispute and cites ~335,701 camera locations on the map. Distinct from the desk’s 16 Sep Micah Lee firmware / hard-coded API-key card (flock-alpr-hardcoded-creds-20260916). No CVE. Primary: The Intercept; wire: Tom's Hardware.
- Product
- Flock Safety ALPR / device location services (ArcGIS-backed)
- Versions
- n/a (unauthenticated access-token / ArcGIS query path reported Nov 2025 disclosure; public map uses Dec 2025 snapshot)
- Exploited in Australia?
- unknown
- Patch to
- Operators and agencies using Flock: confirm vendor has closed unauthenticated token issuance and ArcGIS layer exposure; inventory public map exposure of own sites; treat location data as sensitive (personnel / facility tracking risk). No general end-user patch.
Primary: The Intercept — Flock wants detailed camera map taken down (24 Sep 2026) · Tom's Hardware — unauthenticated flaw / ~335,701 locations (27 Sep 2026)
