| |
# Summary A security researcher discovered critical vulnerabilities in Creative's Sound Blaster Katana V2X speaker that allow attackers within 15 meters to remotely compromise a connected PC, turning the device into a spying tool and attack device without physical access or pairing. The vulnerabilities stem from weak firmware protection—the device uses only a SHA-256 checksum rather than cryptographic signature verification for firmware updates, allowing attackers to flash malicious firmware after bypassing the static authentication key that can be derived from Creative's public app binaries. The same vulnerabilities are confirmed to affect the Katana V2 and likely the Katana SE models.
Read Full Article →
← More Tech news