USB Speaker Vulnerability: A New Way to Infect PCs

A popular USB speaker can be exploited to infect connected devices without any physical interaction.

3 min readCybersecurity

Operating systems are designed with numerous protections to prevent unauthorized commands from external devices. However, a recent discovery reveals that a USB-connected speaker can serve as a gateway for remote code execution if within Bluetooth range. This vulnerability was identified in the Sound Blaster Katana V2X, a highly-rated speaker from Creative Technologies, priced at $283. Researcher Rasmus Moorats uncovered this issue while exploring the speaker's capabilities after purchasing it. He aimed to develop a Linux application that would interact with the device but stumbled upon a significant security flaw. The speaker utilizes a proprietary communication method, which Moorats believes is called Creative Transport Protocol (CTP). This finding raises concerns about the security of devices connected to such speakers, highlighting the need for enhanced protective measures against potential remote attacks.

Cybersecurity