Security1 publisher2 min readPublished
Researchers hijacked cheap smart glasses' cameras by pairing before the owner's phone did
NSB Cyber and Abstract Shield tested two pairs sold for A$60 and A$110 and found more than a dozen flaws, the worst being a Bluetooth pairing step that accepts any device in range while the owner's phone is away.
The Watch · Security desk
What happened
- Researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs of smart glasses, priced at A$60 and A$110, and found more than a dozen flaws across the devices, their app and an associated website.
- The central defect is insecure Bluetooth pairing: with the glasses powered on and not connected to the owner's phone, an attacker could connect first with no password and no meaningful pairing confirmation.
- Once connected, the testers reported they could drive the glasses to capture photos or recordings, copy media already stored on the device, and intercept data moving between the glasses and the phone.
- A Bluetooth-visible device identifier, used against a weakness in the companion app's website, could allegedly return a user's email address and date of birth.
- Voice, text and images sent to the built-in AI went first to a server in Shenzhen and could be forwarded elsewhere depending on the function, and the tests did not establish how that data was later used.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any powered-on, unconnected pair inside Bluetooth range is a camera and microphone an outsider can operate, and the wearer sees no pairing request to decline.
- constraint With no password and no account authentication, there is nothing for device management to enrol, so a BYOD rule written around phones and laptops leaves this hardware out of scope.
- decision Remediation sits with whoever bought the glasses: get the vendor to document a fix, or send the product back.
The vulnerable state is powered on and not yet connected to the owner's phone [3]. A pair sitting in an open case on a desk is in it. So is a pair on a lanyard after the owner's phone walks out of Bluetooth range. The attacker connects first, and the owner gets no prompt to refuse. An attacker needs proximity and timing [3].
One path runs the other way. The researchers reported that another device could be made to look like the victim's glasses and connect to the owner's companion app [5]. That puts an attacker on the phone side of the link, talking to software the owner already trusts.
Both pairs together cost A$170 [17]. The Malwarebytes account does not identify the two models. A policy that names the property will reach them: camera glasses with no clear physical pairing step and no account authentication. Malwarebytes recommends that same screen, plus a published security-contact process and a stated update-support period [15].
Australia's smart-device security standards apply to most consumer smart devices manufactured on or after March 4, 2026, and they require no universal default passwords, a way to report vulnerabilities, and information about the minimum security-update period [10]. Devices made before that date sit outside the requirements [11]. Experts quoted by ABC said the glasses violated Australia's privacy laws and were also likely to breach several sections of the Cyber Security Act [12]. Whether the device standards apply depends partly on when the glasses were manufactured, and the rules have not yet been tested in a known enforcement action [13].
Professor Kimberlee Weatherall, a technology regulation expert involved in the testing, said: "The rules say that the password must be unique. It doesn't even seem like they were applying a password, which might mean that their standards are so low they don't even technically breach that rule, which I find amazing." [14]
The data path drew a separate finding. Weatherall said the failure to identify China in the privacy policy appeared to violate the Australian Privacy Principles [9]. From the server locations and some of the chatbot's answers, the researchers concluded that it relied at least in part on Chinese sovereign AI models [8].
For anyone who already owns a pair, Malwarebytes advised stopping use of the AI and cloud features for sensitive material, stripping unnecessary permissions from the companion app, checking for firmware and app updates, and returning the product if the vendor cannot document a fix [18].
What to watch
- Whether an Australian regulator opens the first enforcement action under the March 4, 2026 smart-device standards, and whether manufacture dates put these glasses inside them.
- Whether either vendor ships firmware that adds a real pairing confirmation, or publishes a security contact at all.
- Whether the two models are named publicly, since the current account describes the class of device and not the products.