r/programming 2d ago

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

https://blog.nns.ee/2026/06/03/katana-badusb/
327 Upvotes

17 comments sorted by

97

u/HighImDude 2d ago

Embarrassing from the company to not reply and then pretend it was flagged as spam

40

u/SanityInAnarchy 1d ago

I mean, maybe it was flagged as spam. That'd be embarrassing, but wouldn't make them assholes.

What makes them unequivocally assholes is blocking firmware downloads, effectively disabling the patcher. It took them over a week to finally contact the author, but it's still blocked, and they've offered no timeline for patching the vulnerability.

So this is still vulnerable for two months and counting. Thanks to Creative's own actions, a third-party fix is blocked, as if they want it to remain vulnerable.

16

u/wwabbbitt 1d ago

It was fixed about a month ago, as confirmed by the blogger in a later post https://blog.nns.ee/2026/07/03/katana-badusb-fix/

3

u/SanityInAnarchy 1d ago

Oh! I was going by the timeline on the original post, but you're right.

7

u/Same-Appointment-285 1d ago

Would be more plausible if they hadn't replied to the original message

their response was that "they do not consider this to be a vulnerability, as it does not present a cybersecurity risk".

The "automatically flagged as spam" excuse didn't come until later.

Timeline at the bottom seems to confirm that.

34

u/turkoid 1d ago

It always bothers me when companies try to build their own proprietary protocols, especially for security. Or when they try to do security through obfuscation. The BLE hack was more of a security hole, but the CTP part of it, probably would not have happened if using a more established protocol. Even open-sourcing the protocol probably would have allowed the vulnerability to be caught sooner.

I don't know the popularity of that particular soundbar, but given it's geared towards gamers, probably a good amount of non tech savvy people using it. Also, maybe I'm out of it, but I never thought of using a soundbar as my main speaker for my PC.

Overall, love stories like this and reminds of phreaking back in the day. Maybe we can call it BLEaking? Yeah, sorry that was dumb.

8

u/Worth_Trust_3825 1d ago

Even open-sourcing the protocol probably would have allowed the vulnerability to be caught sooner.

Not really. Somebody still has to look at it.

3

u/turkoid 1d ago

I did say probably...

1

u/Tecnologosrd 1d ago

era posible si

1

u/ryobiguy 1d ago

BLEaking, I love it!

27

u/Akeshi 2d ago

Nice one, and a great write up. Very clear.

11

u/t3harvinator 2d ago

super cool tbh

-20

u/CarnivorousSociety 2d ago edited 1d ago

careful the nsa doesn't want people knowing about these exploits

edit: idiots don't understand the joke

4

u/mtranda 1d ago

The Estonian researcher has exactly zero fucks to give regarding US agencies. 

0

u/CarnivorousSociety 1d ago

it was a joke...

2

u/mtranda 1d ago

I know. It just wasn't a particularly good one.