Account

The Actual News

Just the Facts, from multiple news sources.

Highly reviewed speaker can be hacked over the air to infect connected devices

Highly reviewed speaker can be hacked over the air to infect connected devices

Summary

A security researcher found that the Sound Blaster Katana V2X speaker can be hacked over Bluetooth without pairing or proof of identity. By sending special commands, an attacker could replace the speaker’s software and then use it to control a connected computer remotely.

Key Facts

  • The speaker connects to PCs, Macs, and Linux devices via USB or Bluetooth.
  • It uses a proprietary protocol called CTP to communicate between devices.
  • Bluetooth connections to the speaker do not require authentication or pairing.
  • One command allows firmware updates without any security checks like code signing.
  • The speaker runs FreeRTOS, an open-source operating system.
  • The researcher modified the speaker’s USB profile to make it act like a keyboard.
  • This allowed the speaker to send keystrokes to the connected PC remotely.
  • Bluetooth is always active on the speaker, even in sleep mode, increasing risk.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.