Creative's Sound Blaster Katana V2X gaming soundbar can be taken over via Bluetooth from 16 yards away, with no pairing and no physical contact required.
Security researcher Rasmus Moorats demonstrated the attack publicly. The device accepts Bluetooth commands without authentication, meaning anyone in range can control it without ever owning or touching the hardware. Creative has reportedly acknowledged the finding but is declining to classify it as a cybersecurity vulnerability.
That classification matters more than it might sound. When a vendor formally labels something a security flaw, it typically triggers a CVE entry, user notification, and a public patch timeline. Refusing the label lets a company acknowledge a problem technically while sidestepping the accountability that comes with a formal disclosure process.
Bluetooth attacks on consumer peripherals rarely make headlines, which is part of why vendors get away with this framing. A soundbar is not a router, but it is on the same wireless band and sitting in the same room.
