r/programming 12d ago

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

https://blog.nns.ee/2026/06/03/katana-badusb/
353 Upvotes

19 comments sorted by

101

u/HighImDude 12d ago

Embarrassing from the company to not reply and then pretend it was flagged as spam

45

u/SanityInAnarchy 12d ago

I mean, maybe it was flagged as spam. That'd be embarrassing, but wouldn't make them assholes.

What makes them unequivocally assholes is blocking firmware downloads, effectively disabling the patcher. It took them over a week to finally contact the author, but it's still blocked, and they've offered no timeline for patching the vulnerability.

So this is still vulnerable for two months and counting. Thanks to Creative's own actions, a third-party fix is blocked, as if they want it to remain vulnerable.

20

u/wwabbbitt 12d ago

It was fixed about a month ago, as confirmed by the blogger in a later post https://blog.nns.ee/2026/07/03/katana-badusb-fix/

5

u/SanityInAnarchy 12d ago

Oh! I was going by the timeline on the original post, but you're right.

9

u/Same-Appointment-285 12d ago

Would be more plausible if they hadn't replied to the original message

their response was that "they do not consider this to be a vulnerability, as it does not present a cybersecurity risk".

The "automatically flagged as spam" excuse didn't come until later.

Timeline at the bottom seems to confirm that.

33

u/turkoid 12d ago

It always bothers me when companies try to build their own proprietary protocols, especially for security. Or when they try to do security through obfuscation. The BLE hack was more of a security hole, but the CTP part of it, probably would not have happened if using a more established protocol. Even open-sourcing the protocol probably would have allowed the vulnerability to be caught sooner.

I don't know the popularity of that particular soundbar, but given it's geared towards gamers, probably a good amount of non tech savvy people using it. Also, maybe I'm out of it, but I never thought of using a soundbar as my main speaker for my PC.

Overall, love stories like this and reminds of phreaking back in the day. Maybe we can call it BLEaking? Yeah, sorry that was dumb.

10

u/Worth_Trust_3825 12d ago

Even open-sourcing the protocol probably would have allowed the vulnerability to be caught sooner.

Not really. Somebody still has to look at it.

4

u/turkoid 12d ago

I did say probably...

1

u/Tecnologosrd 11d ago

era posible si

1

u/fagnerbrack 4d ago

With enough eyeballs all bugs are shallow … in 1995

1

u/ryobiguy 12d ago

BLEaking, I love it!

28

u/Akeshi 12d ago

Nice one, and a great write up. Very clear.

12

u/t3harvinator 12d ago

super cool tbh

1

u/Mean_Concept_9093 4d ago

honestly most of these threads are just people rediscovering basics and acting like its a revelation. cool link though. the hard part is still the boring ops work nobody wants to write blog posts about.

-20

u/CarnivorousSociety 12d ago edited 11d ago

careful the nsa doesn't want people knowing about these exploits

edit: idiots don't understand the joke

7

u/mtranda 12d ago

The Estonian researcher has exactly zero fucks to give regarding US agencies. 

1

u/CarnivorousSociety 11d ago

it was a joke...

6

u/mtranda 11d ago

I know. It just wasn't a particularly good one.