AIToday

Researcher demonstrates over-the-air firmware hack on wireless speaker to execute arbitrary commands on connected PC

Ars Technica AIJun 5, 2026
Researcher demonstrates over-the-air firmware hack on wireless speaker to execute arbitrary commands on connected PC

Summaries like this, in your inbox every morning.

Sign up free →

3 Key Points

  1. Rasmus Moorats discovered he could remotely upload custom firmware to a Katana V2X speaker without pairing, causing it to reboot, flash the firmware, and execute commands on a connected PC by typing keystrokes.

  2. The attack exploits the speaker's USB descriptor set (a report describing a peripheral's capabilities) to make the device appear as a keyboard to connected computers, then uses existing firmware code to send keypresses and commands over the air via Bluetooth.

  3. Bluetooth remains always on for the speaker even in sleep mode with no apparent way to disable it, and a real attacker could disable firmware update routines in both normal and recovery mode, making the malicious firmware impossible to wipe or patch.

Get AI news like this every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Discussion

No discussion yet for this article

Stay ahead with AI news

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.

Get Started Free

Free · takes 30 seconds · unsubscribe anytime

1 minute a day. The AI essentials.

200+ sources · Email / LINE / Slack

Get it free →