• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

How a USB-connected speaker can infect a PC with out ever being touched

Admin by Admin
June 5, 2026
Home Technology
Share on FacebookShare on Twitter


After efficiently changing the firmware with a alternative picture that did nothing greater than show the phrase “patched” on the speaker’s LED show, the researcher acquired to questioning what else a hacker would possibly do. So he turned his consideration to FreeRTOS, the open supply working system that ran the Katana V2X. It contained a set of HID capabilities for permitting the speaker to behave as a human interface system, a classification that features keyboards, mice, and webcams. The speaker carried out a restricted HID that allowed for issues like altering the amount and enjoying or pausing sound, however little else.

The researcher found that he may change the speaker’s USB descriptor set, which is basically a report that informs gadgets concerning the capabilities of a USB- or Bluetooth-connected peripheral. He was in a position to increase the prevailing descriptor set with a second one which reported the speaker being a keyboard. Then he used code already included within the firmware to streamline the method of sending keypresses.

All of this gave Moorats an concept: What if he used his system to ship instructions to the speaker that used the HID to go them alongside to the related PC? After some trial and error, he discovered that he may. In a weblog put up revealed on Wednesday, he wrote:

Chaining all of it collectively, I used to be in a position to completely remotely, over the air, add a customized firmware to my speaker which I hadn’t paired with, which might reboot, flash the customized firmware, and after rebooting sort within the command echo pwned and execute it.



In an actual assault state of affairs, I’d execute the keystrokes for opening powershell.exe or related and paste an really malicious one-liner into that, however as a proof of idea, this was greater than sufficient for me. An actual attacker would additionally doubtless disable the routine for updating the firmware in each regular and restoration mode, making it not possible to wipe the malicious firmware from the system or patch it sooner or later.

That is worsened by the truth that Bluetooth is at all times on for the speaker, even in sleep mode, with no obvious method to disable it.

Earlier than the speaker and USB-connected system can work together, they need to efficiently full a challenge-and-response authentication process. Because the gadgets carry out this handshake mechanically every time the software program boots, this isn’t often an issue for the hacker. In sure circumstances, nevertheless, similar to when the Katana V2X app isn’t open on the related system, it’s a requirement.

Tags: InfectSpeakertouchedUSBconnected
Admin

Admin

Next Post
7 Finest Bill Administration Software program for 2026: My Picks

What are the Greatest Cloud-Based mostly Billing Options for Small Companies?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

UK campaigners amongst 5 denied US visas

UK campaigners amongst 5 denied US visas

December 24, 2025
GGMods Dwell Present and Prize Particulars

GGMods Dwell Present and Prize Particulars

April 16, 2026

Trending.

Nsfw Chatgpt Options – Examples I’ve Used

Nsfw Chatgpt Options – Examples I’ve Used

October 13, 2025
The Obtain: the tech reshaping IVF and the rise of balcony photo voltaic

The Obtain: the tech reshaping IVF and the rise of balcony photo voltaic

May 7, 2026
Digital Detox & Display Time Statistics 2025

Digital Detox & Display Time Statistics 2025

March 28, 2026
How CallPhantom tips Android customers

How CallPhantom tips Android customers

May 8, 2026
Ivanti EPMM CVE-2026-6973 RCE Beneath Energetic Exploitation Grants Admin-Stage Entry

Ivanti EPMM CVE-2026-6973 RCE Beneath Energetic Exploitation Grants Admin-Stage Entry

May 8, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

DeepSeek V4 Pricing and Capabilities

DeepSeek V4 Pricing and Capabilities

June 6, 2026
AI Apps You Can Use Proper Now to Develop Your Web site

AI Apps You Can Use Proper Now to Develop Your Web site

June 6, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved