A security researcher has published a remote exploit for the Creative Sound Blaster Katana V2X, a popular PC soundbar. The attack requires no physical access or pairing and can inject keystrokes from up to 15 meters away.
Exploit chains two critical flaws
The exploit chains two flaws in the Katana V2X. First, the Bluetooth Low Energy interface exposes its command protocol without authentication. Second, the speaker accepts firmware updates without cryptographic signing.
An attacker can flash custom firmware over BLE from up to 15 meters without pairing. The custom firmware adds a keyboard HID descriptor, allowing keystroke injection after reboot. The speaker's Bluetooth radio stays active even in sleep mode.
Creative was notified via SingCERT after direct contact attempts failed. Creative responded that this is not a vulnerability. No patch is coming.
A third-party mitigation tool, v2x-patcher, blocks CTP-over-Bluetooth at the firmware level. However, it may break the Creative mobile app.
The latest official firmware remains vulnerable. Users may use the mitigation tool or disconnect the speaker when not in use.
Source: NotebookCheck

Discussion
0 comments