Skip to main content

Your Sonos or Bose speaker (probably) isn’t haunted, but it could be hacked

Sonos One
Image used with permission by copyright holder
The idea of your internet-connected speakers and other smart devices talking to each other might sound crazy, but it’s more likely than you think. At least it is now that hackers have found a way to play any sound they want on certain speakers from Sonos and Bose, as Wired reports.

Cybersecurity company Trend Micro has found that models from Sonos, including the Sonos One and Sonos Play:1, as well as some Bose SoundTouch speakers, can be found relatively easily by remote attackers. Trend Micro found that between 2,000 and 5,000 Sonos devices could be found online, depending on the time of day, while 400 to 500 Bose systems could be found. Once the speaker is found, an attacker can play any audio of their choice through the speaker without much work.

Recommended Videos

While playing audio doesn’t sound like much of a threat — especially when compared to your smart home devices being made part of a botnet — it isn’t as innocuous as it sounds. Attackers could, for example, use a compromised speaker to play Alexa or Google Home commands. With our homes increasingly hosting these types of devices, and in the case of the Sonos One, having Alexa built in, this could give an attacker free reign over your smart devices.

Please enable Javascript to view this content

Despite the potential consequences that this vulnerability could lead to, for the time being, there don’t seem to be reports of much beyond simple pranks. Earlier this year, a post by a Sonos owner on the company’s community forum complained of a series of spooky sounds emanating from their speaker — first the sound of a door opening, then glass breaking, then a baby crying. Eventually the customer pulled the plug to stop the sound.

Fortunately, this shouldn’t pose a problem for the average Sonos or Bose owner. Most home networks are secure enough to prevent the access needed for this type of attack. If, on the other hand, you’re running a game server or allowing other types of access to your home network from the internet, you might want to tighten up your security settings.

Sonos has issued a patch aimed at fixing this issue, and while Bose has yet to comment on the issue, it’s likely that a similar fix is on the way.

Kris Wouk
Former Digital Trends Contributor
Kris Wouk is a tech writer, gadget reviewer, blogger, and whatever it's called when someone makes videos for the web. In his…
GoldenEar Speakers joins Paradigm, MartinLogan, and Anthem
GoldenEar T66

After the news last month that Bose had acquired the McIntosh Group, we have another interesting shift in the premium audio world. PML Sound International -- the parent company of storied audio brands Paradigm, MartinLogan, and Anthem -- has welcomed GoldenEar Speakers into the fold. It was just under five years ago when it was announced that GoldenEar had been bought by The Quest Group, the owner of AudioQuest and DragonFly, upon the retirement of GoldenEar co-founder Sandy Gross.

Starting January 1, GoldenEar will be known as GoldenEar Studio Inc. PML has announced the operations will pause for the month of January to ensure a smooth transition. During that time, GoldenEar orders will not be processed or fulfilled, with operations resuming on February 3. PML has also assured that "existing warranties and service support will be honored, and they will continue to receive the same level of product quality and customer service when business resumes."

Read more
Here’s how Apple’s AirPods Pro hearing assistance stacks up to professional results
Apple's hearing test in iOS 18.1.

Apple made waves when it announced that its AirPods Pro 2, when combined with iOS 18.1, could fulfill the role of OTC hearing aids. Given that OTC hearing aids can often run as much as $1,500, it seemed too good to be true that the same hearing benefits could be had for just $249 or less. Better yet, given the popularity of Apple's wireless earbuds, there's an excellent chance that those who could benefit already own them (if you live in a country where Apple's hearing aid feature has been approved).

So how good are the AirPods Pro 2 as OTC hearing aids?

Read more
The Amazon Fire TV Stick 4K is the perfect stocking stuffer, and it’s on sale
A promo image of the Amazon Fire TV Stick HD.

If you’re struggling to come up with last-minute gift ideas, an Amazon Fire TV Stick makes for a great stocking stuffer, and it won’t break the bank. And while these streaming devices are pretty cheap, to begin with, the following offer makes buying one all the more appealing:

For a limited time, when you purchase the Amazon Fire TV Stick 4K through Amazon or Best Buy, you’ll only pay $28. At full price, this model sells for $50. We tested this tried and true streamer all the way back in 2020, and reviewer Ryan Waniata said, “Amazon’s Fire TV Stick 4K offers killer features at a great price.”

Read more