NINTENDO SWITCH Unpetrified: Echoes of Nature Console Release Confirmed for Fall 2026 PHONES Huawei Leads China Smartphone Market as Apple Grows Amid 2% Decline GAMES Phasmophobia Gets Deildegast Ghost and 13 Willow Street Rework STEAM Fallout 76 Update 2.28 Released: Infestations Rebalanced and Boss Loot Fixed GAMES Former Forza Director Calls Xbox Game Pass ‘A Real Shame’ GAMES Bethesda Takes Fallout 76 Servers Offline for July 21 Title Update INTEL Kirin 9030 Pro Teardown Shows SMIC N+3 Beats Intel 18A Pitch PLAYSTATION 5 Wreckreation 2 Announced for PS5, Xbox Series, and PC NINTENDO SWITCH Dear Passengers Console Status: PS, Xbox, PC, and Switch Availability XBOX SERIES X Xbox Game Pass Adds 6 New Games in July 2026, Including Halo GAMES Xbox Game Pass Price Cuts to $22.99 as Seven New Titles Join Service GAMES Hunty Zombie July 2026 Reward Codes: Free Items for Roblox Players GAMES Dear Passengers Release News & Demo Details for 2026 Launch HANDHELD GAMING Anbernic RG SP Launches with GBA SP Design and Thinner Chassis

Creative Sound Blaster Katana V2X Remote Exploit Published, No Patch Coming

NicoGG 0 comments 1 min read

A remote exploit for the Creative Sound Blaster Katana V2X allows keystroke injection from up to 15 meters. No patch is coming. Learn about the flaws and mitigation.

Creative Sound Blaster Katana V2X Remote Exploit Published, No Patch Coming
PC HARDWARE

A security researcher has published a remote exploit for the Creative Sound Blaster Katana V2X, a popular PC soundbar. The attack requires no physical access or pairing and can inject keystrokes from up to 15 meters away.

Exploit chains two critical flaws

The exploit chains two flaws in the Katana V2X. First, the Bluetooth Low Energy interface exposes its command protocol without authentication. Second, the speaker accepts firmware updates without cryptographic signing.

An attacker can flash custom firmware over BLE from up to 15 meters without pairing. The custom firmware adds a keyboard HID descriptor, allowing keystroke injection after reboot. The speaker's Bluetooth radio stays active even in sleep mode.

Creative was notified via SingCERT after direct contact attempts failed. Creative responded that this is not a vulnerability. No patch is coming.

A third-party mitigation tool, v2x-patcher, blocks CTP-over-Bluetooth at the firmware level. However, it may break the Creative mobile app.

The latest official firmware remains vulnerable. Users may use the mitigation tool or disconnect the speaker when not in use.

Source: NotebookCheck

Discussion

0 comments

Leave a comment