Ultra-cheap smart glasses found to have serious security flaws, ABC investigation reveals

No password required for Bluetooth hijacking, experts say product likely breaches Australian law

edit
By LineZotpaper
Published
Read Time2 min
Sources2 outlets
A new generation of ultra-cheap AI-enabled smart glasses is exposing users to hackers who can remotely access cameras, microphones, and stored data without a password, according to an investigation by ABC News and independent cybersecurity testing.

Independent testing by cybersecurity experts has revealed a suite of serious vulnerabilities in a new generation of ultra-cheap smart glasses, finding that an attacker can gain full control of the device using only Bluetooth.

David Crees, lead researcher for the testing conducted on behalf of the ABC by NSB Cyber and Abstract Shield, said the glasses had no password protection, allowing anyone with the companion app to log in without authentication. “It shouldn't be possible — it is not possible in pretty much every other proper consumer electronic,” he said.

The ability to hijack a stranger’s glasses was one of more than a dozen flaws discovered in six days of testing the AI-enabled smart glasses, the phone app, and its website. “I would have expected to have found some vulnerabilities… but in this case, there wasn't a single thing that they had done correctly,” Mr Crees said.

Among the key flaws identified: when the glasses are switched on but the owner is not connected, an attacker can “race” to connect first with no barrier; once connected, the attacker can take new photos and recordings, copy stored files, and intercept audio and images being transmitted to the phone. An attacker can also impersonate glasses they do not own and use the device ID—visible over Bluetooth—to look up the user’s email address and date of birth via a separate vulnerability on the app’s website.

Legal experts said the security failures likely breach the Privacy Act, Australian consumer law, and the government’s new Cyber Security Act. Kimberlee Weatherall, a tech regulation specialist at the University of Sydney, called the findings “really disturbing.” “They don’t seem to have encrypted it, they don’t seem to have put passwords on it, they don’t seem to have put even basic protections on the information that’s on the website,” she said. “It’s a really clear breach [of the Privacy Act].”

There has been growing public backlash to the recent influx of cheap smart glasses in Australia. The ABC has invited members of the public who have been filmed without consent by such devices to share their experiences.

§

Analysis

Why This Matters

  • Australian consumers using these glasses have their photos, videos, and audio exposed to any attacker within Bluetooth range, creating a serious privacy risk.
  • The findings suggest the product may violate multiple Australian laws, which could lead to enforcement action by regulators such as the OAIC or ACCC.
  • The vulnerabilities highlight broader concerns about the rush to market of cheap AI-powered wearables with little to no security scrutiny.

Background

Ultra-cheap smart glasses have recently entered the Australian market, offering features like voice control, photo capture, and video recording at a fraction of the cost of established brands like Meta's Ray-Ban Stories. However, unlike those mainstream products, many budget alternatives have not undergone rigorous security testing. The ABC investigation commissioned independent penetration testing to assess the security of one such product, revealing a complete absence of basic protections such as encryption and authentication.

Key Perspectives

Cybersecurity researchers: David Crees and the NSB Cyber/Abstract Shield team found that none of the security measures were implemented correctly. The ease of Bluetooth hijacking represents a fundamental design failure. Legal experts: Kimberlee Weatherall argues the flaws clearly breach Australian privacy and consumer laws, and possibly the new Cyber Security Act, which imposes obligations on smart device manufacturers. Privacy advocates and consumers: The ability for strangers to surreptitiously record and access data raises alarm about surveillance, especially in public spaces. Growing public backlash suggests demand for stronger protections.

What to Watch

  • Regulatory action: whether the Office of the Australian Information Commissioner (OAIC) or the ACCC investigates and issues fines or recalls.
  • Industry response: whether manufacturers of cheap smart glasses will issue patches or recalls to address the vulnerabilities.
  • Future legislation: the Cyber Security Act may be tested early in this case, potentially setting a precedent for IoT security enforcement in Australia.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.