this post was submitted on 03 Jun 2026
169 points (98.3% liked)
Technology
85134 readers
4484 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Awesome write up.
Allowing arbitrary firmware updates without any signature validation, over Bluetooth, even unpaired and in sleep mode, and without any authentication is absolutely wild and should be criminal negligence.
What a foolish response. The guy wasn't asking for money and gave them everything they would need to make a patched firmware.
"does not present a cybersecurity risk..." to them.
I suppose that depends on your definition of a cybersecurity risk. Unfortunately it likely won't matter to them unless it starts affecting their bottom line.
"It's not a vulnerability, no I'm not crying"
"You're the vulnerability"
Came to comment the same.
That and it has a microphone built in.
Well I won't be buying another creative product ever again
I don't understand how this can still happen with a well known brand in 2026. Personally the microphone is the least concerning aspect of this finding, since a Bluetooth connection would still be required. With more dedicated research, the BadUSB aspect is far more concerning in my book. Plug the speaker into a computer, even once and only to charge, and the computer is pwned? Preventing any future patching? I don't know how I could ever trust one of these devices going forward.