tech

How a USB-connected speaker can infect a PC without ever being touched

Seller of the Sound Blaster Katana V2X doesn’t consider the behavior a vulnerability.

How a USB-connected speaker can infect a PC without ever being touched

TL;DR

  • A security flaw in the Creative Sound Blaster Katana V2X speaker allows remote code execution on connected PCs via Bluetooth.
  • Attackers can upload custom firmware without pairing or authentication, and the speaker's firmware updates lack code signing.
  • The speaker can be made to act as a keyboard, allowing remote command execution on the connected PC.
  • Bluetooth is constantly active on the speaker, even in sleep mode, and cannot be disabled.
  • Creative Technologies has stated they do not consider this a vulnerability.
  • The attack requires the attacker to be within Bluetooth range of the speaker.