Independent testing by cybersecurity experts has revealed a suite of serious vulnerabilities in a new generation of ultra-cheap smart glasses, finding that an attacker can gain full control of the device using only Bluetooth.
David Crees, lead researcher for the testing conducted on behalf of the ABC by NSB Cyber and Abstract Shield, said the glasses had no password protection, allowing anyone with the companion app to log in without authentication. “It shouldn't be possible — it is not possible in pretty much every other proper consumer electronic,” he said.
The ability to hijack a stranger’s glasses was one of more than a dozen flaws discovered in six days of testing the AI-enabled smart glasses, the phone app, and its website. “I would have expected to have found some vulnerabilities… but in this case, there wasn't a single thing that they had done correctly,” Mr Crees said.
Among the key flaws identified: when the glasses are switched on but the owner is not connected, an attacker can “race” to connect first with no barrier; once connected, the attacker can take new photos and recordings, copy stored files, and intercept audio and images being transmitted to the phone. An attacker can also impersonate glasses they do not own and use the device ID—visible over Bluetooth—to look up the user’s email address and date of birth via a separate vulnerability on the app’s website.
Legal experts said the security failures likely breach the Privacy Act, Australian consumer law, and the government’s new Cyber Security Act. Kimberlee Weatherall, a tech regulation specialist at the University of Sydney, called the findings “really disturbing.” “They don’t seem to have encrypted it, they don’t seem to have put passwords on it, they don’t seem to have put even basic protections on the information that’s on the website,” she said. “It’s a really clear breach [of the Privacy Act].”
There has been growing public backlash to the recent influx of cheap smart glasses in Australia. The ABC has invited members of the public who have been filmed without consent by such devices to share their experiences.