RESEARCHERS from NSB Cyber and Abstract Shield found more than a dozen security and privacy flaws while testing two inexpensive smart-glasses models costing A$60 and A$110. The main weakness was insecure Bluetooth pairing: when the glasses were switched on but not connected to their owner’s phone, another person could connect without a password or meaningful confirmation.
According to reporting cited by Malwarebytes, a connected attacker could control the glasses to take photographs or recordings, copy stored media and intercept data exchanged with the phone. They could also make another device impersonate the glasses and connect it to the owner’s mobile app.
The testing found that a Bluetooth-visible device identifier could potentially be combined with a weakness in the associated website to obtain a user’s email address and date of birth. Voice, text and images submitted to the glasses’ built-in AI were first sent to a server in Shenzhen and could be forwarded elsewhere, although the researchers did not establish how the data was subsequently used.
Experts involved in the testing said the undisclosed data handling could breach Australia’s Privacy Principles, while any breach of the country’s smart-device security standards would partly depend on when the glasses were manufactured. Those standards cover most consumer smart devices made on or after 4 March 2026, but have not yet been tested in a known enforcement action.
Owners are advised to avoid sensitive AI or cloud use, remove unnecessary app permissions, install available firmware and app updates, and consider returning devices if the manufacturer cannot document a fix. Malwarebytes also recommends avoiding cheap camera glasses without a physical pairing step, account authentication, a security-contact process and a stated update-support period.