TP-Link Patches Tapo Camera Flaws as Google Confirms Pixel Zero-Days
TP-Link released firmware to fix two high-severity Tapo C200 camera flaws that could let attackers hijack admin sessions and view video, while Google said some Pixel owners were targeted in zero-day modem attacks.
Opswat found the two Tapo C200 bugs and disclosed them to TP-Link, TechRadar reported. The first, CVE-2026-15315, has a severity score of 8.7 out of 10 and allows unauthenticated attackers to obtain valid admin sessions without a password, which would let them manage the device and view its stream. The second, CVE-2026-15316, has a severity score of 7.1 out of 10 and allows attackers to send oversized encrypted ciphertext values that may trigger exception handling failures and crash or restart the device. According to the National Vulnerability Database, successful exploitation may temporarily disrupt HTTPS management and monitoring until the service recovers.
Opswat disclosed its findings to TP-Link in mid-April 2026, and TP-Link began working on a fix in early July 2026, according to TechRadar. On Aug. 18, 2026, the company released firmware version V5_1.4.6, which addresses both flaws. Users were advised to install the update as soon as possible. The researchers did not say whether either flaw had been exploited in the wild. The C200 is advertised as a security camera, baby monitor and pet camera, with 1080p video, two-way audio, night vision, motion detection, cloud and SD card storage, and integrations with Alexa and Google Home. TP-Link says the Tapo app has more than 13 million users, and Google Play shows more than 10 million downloads. On Amazon, the C200 is listed as the top-rated product in its category, with more than 3,000 purchases this month alone.
“Camera bugs always get attention because of the ‘spy factor,’ but they usually sound cooler and scarier than they actually are,” Dahvid Schloss, chief operating officer at Suzu Labs, told TechRadar. He said the main reason not to worry about this exploit is that it requires local network access, meaning an attacker would need to be on the user’s Wi-Fi or already control a device on it. If a camera has been port-forwarded to the internet, that is a bigger design issue and probably should be a concern, but it is not a common setup for the everyday home user, Schloss said. He still recommended patching the camera.
Google said Tuesday that a bug in Pixel smartphones’ software, tracked as CVE-2026-58704, had been exploited in limited and targeted cyberattacks and has now been patched, TechCrunch reported. The flaw was found in the Pixel phones’ modem, which connects the device to the internet. Exploiting it could allow an attacker to gain access beyond the sandboxed walls of the modem and into broader phone data, a vulnerability known as privilege escalation. The bug could be exploited silently and without any interaction from the phone owner in a zero-click attack, meaning a victim did not need to click a link or open a file.
Google did not say who was exploiting the bug, and a Google spokesperson did not return a request for comment, according to TechCrunch. The report said it is not uncommon for bugs like this one to be abused by surveillance vendors, such as spyware makers, who sell access to their data-stealing software to governments and law enforcement agencies.