Independent testing of ultra-cheap AI smart glasses sold in Australia found the devices can be hijacked by a nearby attacker using only Bluetooth, with no password required, according to an investigation published on Tuesday.
The testing, carried out for the ABC by cybersecurity firms NSB Cyber and Abstract Shield, examined two products: a $60 pair sold through Temu and a $110 pair supplied by Sydney-based importer BDI Technology via Big W Marketplace. Lead researcher David Crees said there wasn't a single thing they had done correctly.
Crees, who tested the devices, the HeyCyan companion app and its website over six days, identified more than a dozen vulnerabilities. Among them: an attacker can "race" to connect to unpaired glasses before the owner does; once connected, they can trigger new recordings or copy stored photos and video; audio and images can be intercepted mid-transmission to the owner's phone; and a visible device ID can be used to look up a user's email address and date of birth through a separate flaw on the app's website.
Legal experts said the flaws likely breach the Privacy Act, Australian Consumer Law and the Cyber Security Act, which took effect in March. University of Sydney tech regulation specialist Kimberlee Weatherall said it's a really clear breach of the privacy act. She noted the rules require unique passwords, and the devices did not appear to have passwords at all.
Testing also found user data – including anything spoken, typed or submitted as images to the built-in AI companion – was routed first to a server in Shenzhen, and in some cases onward to other Chinese or US servers, without the practice being disclosed in the privacy policy. Evan Vougdis of NSB Cyber, who oversaw the research, said is it being used for surveillance?
The findings land amid a wider, unsettled regulatory picture for the category. Australia's eSafety Commissioner issued advice to industry on Aug. 31 calling for tamper-proof recording indicators, automatic face-blurring by default and delayed, moderated livestreaming, warning the devices could facilitate image-based abuse, stalking and doxing when combined with facial recognition, according to a summary published by MLex. But Attorney-General Michelle Rowland has ruled out banning smart-glasses imports, telling the ABC the government does not want a regulatory environment that's playing "Whac-A-Mole" with each new device, and that local councils and businesses can instead set their own conditions of entry. Greens Senator Sarah Hanson-Young has pushed the opposite position, with a spokeswoman saying the senator supports a ban on unregulated smart glasses until stronger laws are introduced, according to ChannelNews.
The ABC said some flaws appeared to have been patched after the findings were shared. Crees said a full fix was not realistic. You'd have to update 300 different brands of glasses and the app and the website, he said, adding that the only real solution that I see is a recall.
BDI Technology, also listed as a supplier to Dick Smith and on Big W's Marketplace platform, told the ABC it had stopped selling smart glasses. Australian Privacy Commissioner Carly Kind said there has been a really extreme backlash to these technologies, and that companies concerned about their reputation would do well to listen to that community concern.