CVE-2026-81330: Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
Affected Software
Event History
Frequently Asked Questions
Who can realistically intercept the video stream?
An attacker within local wireless range may capture the unencrypted UDP traffic and reconstruct the live video stream. The provided data does not indicate that internet access, authentication, or user interaction is required.
What evidence can be used to determine whether the stream is exposed?
Capture traffic while the C6 ear camera is streaming to the EarVision Android application and inspect for UDP packets containing reconstructable JPEG or WEBP video frames. The application manifest also permits cleartext traffic.
What can be done if a fix is not immediately available?
Limit use of the camera and application in environments where untrusted parties could be within local wireless range. Avoid transmitting sensitive live video over the affected connection until transport encryption is available.