Security researcher Rasmus Moorats disclosed multiple flaws in the Creative Sound Blaster Katana V2X that allow an attacker within roughly 15 meters to remotely alter the speaker over Bluetooth Low Energy without pairing or physical access. The attack chain relies on the device exposing its proprietary Creative Transport Protocol over BLE without authentication and accepting firmware images based only on a CHK2 SHA-256 checksum field, with no cryptographic signature verification. Moorats showed that an attacker can push modified firmware to the soundbar over the air while preserving normal speaker functionality.
The proof of concept turned the USB-connected soundbar into a BadUSB-style device that re-enumerates as a keyboard and injects keystrokes into a connected PC, and also demonstrated the potential to use the speaker as a covert audio surveillance device. Creative reportedly took weeks to respond and said it did not consider the issue a cybersecurity risk, leaving no official patch available at publication time. As a partial mitigation, Moorats released an unofficial tool that patches the official firmware over USB to disable CTP over Bluetooth, though it may break the mobile app and does not address the underlying lack of firmware authenticity controls.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-02, Creative released firmware version 1.21.260630.1200 for Sound Blaster Katana devices, adding checks for appended bytes after CHK3 and limiting section parsing to payload_size. According to the researcher, these changes are sufficient to prevent the demonstrated firmware-signature bypass, while fixes for Bluetooth CTP authentication are still pending.
The researcher released an unofficial patching tool that disables CTP-over-Bluetooth by patching and reflashing the official firmware over USB. The mitigation reduces exposure but may break the mobile app and does not fully address the underlying design weaknesses.
On 2026-06-03, a researcher publicly disclosed multiple vulnerabilities in the Creative Sound Blaster Katana V2X that allow unauthenticated attackers within about 15 meters to modify firmware over Bluetooth without pairing or physical access. The disclosure showed the device could be turned into a covert microphone and a USB HID "Rubber Ducky" that injects keystrokes into a connected PC.
The researcher reported the Sound Blaster Katana V2X vulnerabilities to Creative through support channels and via SingCERT. Creative later responded that it did not consider the issue a cybersecurity risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
blog.nns.ee
Open sourcetomshardware.com
Open sourceblog.nns.ee
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.