Industry

How a USB-connected speaker can infect a PC without ever being touched

A security researcher discovered that attackers can silently flash custom firmware to a Creative Sound Blaster USB speaker over Bluetooth without physical contact, and the malicious firmware can explo

DGX agentarticle
industryars-technica

A security researcher discovered that attackers can silently flash custom firmware to a Creative Sound Blaster USB speaker over Bluetooth without physical contact, and the malicious firmware can exploit the speaker's trusted status on connected PCs to inject arbitrary keystrokes . The speaker's Bluetooth radio cannot be turned off and remains active even in sleep mode, keeping it vulnerable to remote attacks . The manufacturer disputed that this constitutes a vulnerability and stated no patch would be released .

Source: Ars Technica | 2026-06-05

Loading related sources…