Share This Article
Anyone within Bluetooth range can seize control of a AU$60 pair of AI glasses sold through Temu, with no password required. That conclusion comes from an ABC News investigation published on September 22 by security firms NSB Cyber and Abstract Shield.
The testing fell to Abstract Shield’s David Crees, who logged more than a dozen defects in six days, with some in the frame, others in the phone app, others on the website behind it. His verdict to the broadcaster: “There wasn’t a single thing that they had done correctly.” Some flaws were patched after the findings were shared; most were not.
The worst of the flaws is the missing pairing password. Switch them on before they link to the owner’s handset and anyone within Bluetooth range can claim the connection, then pull down stored photos and clips, shoot fresh ones, or tap the images and sound passing through.
An unpaired pair also pushes its device ID out over the air for anything nearby to catch, and that identifier turns out to unlock personal data on the site behind the HeyCyan companion app: the owner’s email address and date of birth. The audio, text and images a wearer feeds the built-in assistant go first to a server in Shenzhen, then on to another Chinese machine or the United States; Singapore is the only country named in HeyCyan’s privacy policy.
Two pairs were examined: the AU$60 Temu set and an AU$110 model from importer BDI Technology, which no longer sells smart glasses. Both run HeyCyan, from Shenzhen Qingcheng Future Technology.
Australian privacy law is what the devices breach, according to Kimberlee Weatherall, whose work at the University of Sydney centers on technology regulation; David Crees argues only a recall will fix the rest.
Source: Mixed News
Source: ABC News


