Apart from the privacy concerns around smart glasses, researchers have found that some cheap brands come with barely any security at all.
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website.
The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation.
After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone. An attacker could also make another device appear to be the victim’s glasses, allowing it to connect to the owner’s mobile app.
The testing also found that a Bluetooth-visible device identifier could allegedly be used with a weakness in the app’s website to retrieve a user’s email address and date of birth.
The research uncovered another privacy issue. ABC reports that voice or text submitted to the built-in AI, along with images sent to it, was first transmitted to a server in Shenzhen and could be forwarded elsewhere, depending on the function. The tests did not establish how the data was subsequently used.
The server locations, combined with some of the AI’s answers to specific questions, led researchers to conclude that the chatbot companion relied at least in part on Chinese sovereign AI models. Professor Kimberlee Weatherall, a technology regulation expert involved in the testing, said the failure to identify China in the privacy policy appeared to violate the Australian Privacy Principles,
The timing of the testing is also relevant because Australia’s smart-device security standards apply to most consumer smart devices manufactured on or after March 4, 2026. They require, among other measures, no universal default passwords, a way to report vulnerabilities, and information about the minimum security-update period. Devices made before that date are outside the requirements.
Experts quoted by ABC said the devices violated Australia’s privacy laws and were also likely to breach several sections of the Cyber Security Act. However, whether the new smart-device standards apply would depend partly on when the glasses were manufactured, and the rules have not yet been tested in a known enforcement action.
Professor Weatherall said:
“The rules say that the password must be unique. It doesn’t even seem like they were applying a password, which might mean that their standards are so low they don’t even technically breach that rule, which I find amazing.”
What to do
We’re not fans of smart glasses, expensive or cheap. But if you own a pair:
- Avoid pairing or using inexpensive camera glasses that lack a clear physical pairing step, account authentication, a published security-contact process, and a stated update-support period.
- Stop using their AI or cloud features for sensitive material, remove unnecessary permissions from the companion app, check for firmware and app updates, and consider returning the product if the vendor cannot document a fix.
- Ask permission before recording people, and check your local laws to understand what is and isn’t allowed.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Article Link: Some cheap smart glasses are a security disaster | Malwarebytes