Cheap Smart Glasses Found Wide Open to Bluetooth Snooping

Researchers found more than a dozen flaws in two budget smart glasses pairs, including Bluetooth pairing that let an attacker connect first and pull photos and recordings.

Sep 22, 2026
3 min read
Technobezz
Cheap Smart Glasses Found Wide Open to Bluetooth Snooping

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

Two pairs of budget smart glasses, priced at A$60 and A$110 (roughly US$42 and US$78), were tested by security researchers and found to carry more than a dozen flaws spread across the glasses themselves, the companion app, and the vendor's website. The most serious problem sits in how the glasses pair over Bluetooth: there is no password, and an attacker who gets to a device before its owner can link up without any real confirmation step. Malwarebytes Labs published the findings, which were first reported by ABC Australia.

Once connected, an attacker was reportedly able to do several things. The intruder could take new pictures or recordings through the glasses, pull media already stored on them, and read data as it moves between the glasses and the phone. The same weakness also allowed a spoofed device to impersonate the victim's glasses to the owner's app.

A second path to user data ran through the web side. A Bluetooth-visible identifier on the glasses, combined with a flaw in the app's website, could allegedly expose an owner's email address and birth date.

The AI features raise their own questions. Voice, text, and images submitted to the built-in assistant were first sent to a server in Shenzhen, and depending on which function was in use, that data could be passed on further. Professor Kimberlee Weatherall, a technology regulation expert, said the privacy policy never named China. She also pointed at the pairing gap: "The rules say that the password must be unique. It doesn’t even seem like they were applying a password, which might mean that their standards are so low they don’t even technically breach that rule, which I find amazing."

Australia's smart-device security standards, which took effect for devices manufactured on or after March 4, 2026, require manufacturers to avoid universal default passwords, publish a way to report vulnerabilities, and disclose how long they will ship security updates. Units built before that date fall outside those obligations. Experts cited in the ABC report said the glasses appeared to break Australia's privacy laws and likely ran afoul of several sections of the Cyber Security Act, though whether the rules apply depends in part on when the units were made. No enforcement action has tested the standards yet, and the report does not say whether they cover the specific glasses tested.

The testing was carried out by researchers from NSB Cyber and Abstract Shield.

For buyers, the practical advice is blunt. Skip cheap camera glasses that do not require a physical step to pair. Keep sensitive material away from their AI and cloud features, trim unnecessary app permissions, and check for updates. If a seller cannot document a fix, returning the product is a reasonable option. Anyone recording other people should ask first and check local law.

The report lands in a stretch of coverage about cheap tools and hijacked accounts. Malwarebytes Labs recently described over 100 subscription sites tied to a single toolkit, and earlier reported a verified HBO Max Reddit account that ran 108 malicious ads in roughly 48 hours.

Share