Some Wyze security camera owners reported Friday that they were unexpectedly able to see webcam feeds that weren’t theirs, meaning that they were unintentionally able to see inside of other people’s houses. A Wyze spokesperson tells The Verge that this was due to a web caching issue.
Earlier on Friday, users on Reddit made posts about the issue. “Went to check on my cameras and they are all gone be replaced with a new one... and this isn’t mine!” wrote one user. “Apologies if this is your house / dog... I don’t want it showing up as much as you don’t want it!”
“I am able to click the events tab and see ALL the events on this random person’s camera INSIDE their house,” wrote another.
“I don’t know why, but I can see someone else’s camera,” wrote another.
The user reports indicated that they were seeing the other feeds through Wyze’s web viewer at view.wyze.com. A Wyze employee told a user on Reddit that the page is “currently under maintenance” and that “we are working on this and will update when it’s available again.” Wyze’s status page posted a similar message on Friday at 5:44PM ET.
A Wyze customer support agent confirmed to me that the company has an issue with its online camera portal — one where people were actually able to see other customers’ camera feeds. “While we work to get this resolved, Wyze Web View functionality may be limited or unavailable,” they told me. The agent was not able to provide an estimate for when the issue would be fixed.
“We and our team are already working to improve our security and to investigate the root cause of this,” the agent said. When I asked if they could share what those improvements might be, the agent responded: “I cannot disclose any further information.”
After we published this story, Wyze spokesperson Dave Crosby shared a statement explaining what happened. Although Crosby says the issue is resolved and that view.wyze.com is “back up and running,” the status page still says view.wyze.com is under maintenance as of Saturday morning. (Crosby says the company will update the status page “shortly.”)
Here is Crosby’s statement:
This was a web caching issue and is now resolved. For about 30 minutes this afternoon, a small number of users who used a web browser to log in to their camera on view.wyze.com may have seen cameras of other users who also may have logged in through view.wyze.com during that time frame. The issue DID NOT affect the Wyze app or users that did not log in to view.wyze.com during that time period.
Once we identified the issue we shut down view.wyze.com for about an hour to investigate and fix the issue.
This experience does not reflect our commitment to users or the investments we’ve made over the last few years to enhance security. We are continuing to investigate this issue and will make efforts to ensure it doesn’t happen again. We’re also working to identify affected users.
Crosby added that the company’s “early evidence” is that about 10 users’ feeds could be seen by others. I’ve asked how many people may have seen those people’s feeds.
In March 2022, Wyze revealed that it had been aware of a security vulnerability for three years that could have let bad actors access WyzeCam v1 cameras, but quietly discontinued the camera rather than telling customers about it.
Update September 9th, 8:05AM ET: Added further details from Wyze.