A Creative soundbar can be hacked over Bluetooth and made to type on your PC like a keyboard. From up to 15 meters away, with no password, an attacker can make the soundbar send key presses to a connected PC. If that PC takes them, the attacker can open apps, run programs, or pull down malware. In theory, custom code could even switch on the speaker's own microphone and use it to listen in.
Security researcher Rasmus Moorats found the flaw in the Creative Sound Blaster Katana V2X, a soundbar that connects to your computer with a USB cable. The attacker never has to touch it. They just have to be nearby.
The trick works because your PC trusts anything plugged in as a keyboard. The soundbar can act as one, so once it starts sending key presses, the computer types them out as if you did it yourself.
Why it was so easy
Creative's app sends the speaker commands to change sound, lighting, and inputs. Over USB those commands need a secret key, but Moorats says that key can be pulled straight out of the app's own files, so the lock barely protects anything. Bluetooth was wide open. The speaker took orders from any nearby device, with no pairing and no check that the sender was allowed.
He also loaded his own changed firmware, the low-level software baked into the device, and the only thing guarding it was a checksum that confirms a file has not been damaged but never checks who made it. So a hand-edited version sailed right through.
Which models are affected
Moorats confirmed the attack on the Katana V2X, and a later update confirms the older Katana V2 is open to it the same way. The Katana SE is built a little differently, but he thinks it is probably at risk too. For now the speaker's Bluetooth stays on with no clear way to turn it off.
How Creative responded
Moorats says the agency handling his report told him Creative did not see the bug as a security risk. He then published his research and a patch that blocks the Bluetooth commands. He says Creative then pulled the firmware downloads the patch relied on, leaving owners with no fix. On June 18 the company said it is building fixes, with no date set.





