LONDON, 29 AUG 2026 — Sales of the HMD Fuse, a smartphone marketed on being unusually safe for children, have been paused after a researcher found vulnerabilities that could expose sensitive data including users' live locations.

The device combines technology from HMD, SafeToNet and Xplora, including AI intended to detect nudity on the device and block explicit images before they can be created or shared. The British government had pointed to SafeToNet's approach as a promising form of device-level child protection.

The failure is the inverse of the promise

A phone sold on child safety that could expose the child's live location is more than a security bug. It is a failure of the product's entire premise.

Location is the most sensitive category a child's device holds. It is also the feature parents specifically buy these phones for, which means the data is not incidental — it is collected deliberately, continuously, and in a form designed to be retrievable.

A general-purpose phone with the same flaw would be serious. For a device whose whole purpose is protecting a minor's data it is a critical failure, because the buyer's alternative was a phone that collected less in the first place.

PausedSales, pending investigation
Live locationAmong the data reportedly exposed
Three vendorsHMD, SafeToNet, Xplora
Cited by governmentSafeToNet's approach highlighted

Three companies, one product, and a seam between them

The device is an integration. HMD makes the hardware, SafeToNet supplies the content-safety technology, Xplora contributes its own components, and the child-safety proposition is the combination.

Integrations of this kind concentrate risk at the joins. Each vendor tests its own part against its own threat model, and the interfaces between them belong to everybody and therefore to nobody. Location data crossing from one company's component to another's service is precisely the sort of thing that has an owner on paper and no owner in practice.

Nothing published so far establishes where these particular flaws sat. The structure matters anyway, because any fix will require all three companies to agree on it.

Safety features enlarge the attack surface

The uncomfortable point is that protective features are themselves a form of collection.

On-device nudity detection has to see every image. Content filtering works by inspecting what is viewed, and location reassurance requires knowing where the child is at every moment. Each capability that reassures a parent creates a store of exactly the data that would most harm the child if it escaped.

Child-safety phones solve a real problem, so none of this is an argument against the category. It is an argument that their security bar has to sit higher than an ordinary handset's rather than lower. The marketing for these devices sells reassurance, and reassurance is not a discipline that produces careful engineering.

The instinct for on-device processing is the right one. Analysing an image on the phone rather than uploading it is the privacy-preserving choice. The instinct does not survive if the device then leaks by another route.

What to ask before buying one of these

The category is not going away, and most parents evaluating it have no way to assess the engineering. Four questions do most of the work and none requires technical knowledge to ask.

Where does the analysis happen? A device that examines images on the phone and sends nothing is structurally safer than one that uploads for inspection, whatever either promises about handling.

What is retained, and for how long? Live location shared with a parent in the moment is a different exposure from a location history stored on a company's servers for months. Vendors often describe both as location sharing.

Can the vendor's staff see it? Every monitoring product has an administrative interface, and the answer determines whether a breach at the company exposes your child or merely the service.

What happens when you stop paying? A subscription that lapses should end collection and delete what was gathered. Frequently it ends the parent's access while the data remains.

A vendor whose documentation answers all four plainly has thought about them. Where the answers come back as reassurance rather than as mechanism, treat that as the answer.

Government endorsement is not assurance

The British government having highlighted the underlying approach is the detail with the longest reach.

Officials pointing to a technology as promising is a statement about a policy direction, not a security certification. No government tested this handset, and nothing about being cited in a policy discussion implies a code review.

Parents do not read it that way, and neither do procurement officers. A product that can say it was recognised by government acquires a credibility it did not earn on the merits, which is a well-understood hazard of official enthusiasm for a named vendor.

The remedy is dull and specific. Where a state promotes a category, it should say plainly that it is endorsing an approach rather than assuring a product, and it should say so in the same sentence.

What pausing sales does and does not achieve

Halting sales during an investigation is the right call and it addresses only new buyers.

Devices already in children's hands remain in service, running the affected software, until a fix ships and is installed. The most exposed users, children carrying these phones now, are therefore untouched by the only action taken so far. No timeline for a patch has been published.

Parents who own one face a difficult decision, because the alternatives have their own problems. The proportionate step is not to discard the phone but to turn off any feature not actually being used — particularly continuous location sharing — until the companies say what was fixed and when.

What it means from here

For families in this region, the category is arriving alongside the wider push on children and phones. Malaysia's under-16 age verification scheme, Slovakia's protected mode for teenagers and Meta's youth safety settlement all point the same way, and the commercial answer to that pressure is more monitoring software on more children's devices.

With any such product, ask where the data goes and who holds it. A device that keeps analysis local and stores nothing is a different risk from one that maintains a live location feed on a company's servers, and both are sold with the same word.

HMD has published neither a patch nor a timeline for one. Until it does, the least-collecting configuration is the safest thing available to a parent, whatever the packaging on the alternatives says.