NINTENDO SWITCH 2 Maneater 2 Announced for 2027 Launch on Switch 2, PS5, and PC CONSOLES Square Enix TGS 2026 Lineup Features Dragon Quest VII and Kingdom Hearts IV PLAYSTATION 5 Konami Rhapsody in Scarlet Announced for PS5, Xbox Series, and PC GAMES Naughty Dog Confirms The Last of Us Franchise Is Not Done AMD NBA 2K27 DLSS 5 Benchmarks Show 60% Performance Hit on RTX 5090 GAMES FromSoftware Avoids Fixed Game Formula, Miyazaki Says Fresh Ideas Rule ACCESSORIES Sony GTA 6 DualSense Controllers Launch November 19 for $85 CONSOLES Final Fantasy Resonance Brings HD-2D to PS5, Xbox, Switch 2, PC NINTENDO SWITCH 2 Maneater 2 Announced for PS5, Xbox Series, Switch 2, and PC GAMES Arma Reforger Update 1.080.013 Fixes Crashes and Visual Glitches PLAYSTATION 5 GTA 6 Netflix Deep Dive Drives 33% PS5 and 34% Xbox Sales in UK PLAYSTATION 5 Konami’s Rev. NOiR RPG Confirmed for PlayStation 5 in 2027 PLAYSTATION 5 Gundam Rogue Orbit Sets March 5, 2027 Launch for PS5, Xbox, PC CONSOLES Vampire Survivors Hotfix Fixes Glitches on Consoles

Creative Sound Blaster Katana V2X Remote Exploit Published, No Patch Coming

NicoGG 1 min read

A remote exploit for the Creative Sound Blaster Katana V2X allows keystroke injection from up to 15 meters. No patch is coming. Learn about the flaws and mitigation.

Creative Sound Blaster Katana V2X Remote Exploit Published, No Patch Coming
PC HARDWARE

A security researcher has published a remote exploit for the Creative Sound Blaster Katana V2X, a popular PC soundbar. The attack requires no physical access or pairing and can inject keystrokes from up to 15 meters away.

Exploit chains two critical flaws

The exploit chains two flaws in the Katana V2X. First, the Bluetooth Low Energy interface exposes its command protocol without authentication. Second, the speaker accepts firmware updates without cryptographic signing.

An attacker can flash custom firmware over BLE from up to 15 meters without pairing. The custom firmware adds a keyboard HID descriptor, allowing keystroke injection after reboot. The speaker's Bluetooth radio stays active even in sleep mode.

Creative was notified via SingCERT after direct contact attempts failed. Creative responded that this is not a vulnerability. No patch is coming.

A third-party mitigation tool, v2x-patcher, blocks CTP-over-Bluetooth at the firmware level. However, it may break the Creative mobile app.

The latest official firmware remains vulnerable. Users may use the mitigation tool or disconnect the speaker when not in use.

Source: NotebookCheck