Security researchers disclosed a flaw in a popular line of smart home cameras that allowed unauthorized access to live video feeds through weaknesses in the vendor's cloud authentication service.

The vulnerability let attackers enumerate device identifiers and hijack streaming sessions without triggering owner notifications. Researchers estimate millions of devices were exposed before the fix.

The vendor has deployed mandatory firmware updates and rotated device credentials, and says it has found no evidence of large-scale exploitation, though it acknowledged targeted abuse cannot be ruled out.

The episode adds to mounting scrutiny of consumer IoT security, with regulators in several markets moving toward mandatory security standards for connected devices.