Skip to main content
  1. Home
  2. Computing
  3. News

Sennheiser’s flawed headphone software is a Trojan horse hackers could exploit

Add as a preferred source on Google
Bill Roberson/Digital Trends

Though you may not expect headphones to pose a cybersecurity risk, German-based security firm Secorvo discovered that Sennheiser headphones could be used as a Trojan horse that potentially opens up your computer to hackers. Fortunately, the problem isn’t hardware related, as the headphones themselves are safe to use. Instead, the security flaw exists within Sennheiser’s HeadSetup software and how it installs and manages encrypted certificates on your PC.

According to researchers, Sennheiser’s desktop software was installing a self-signed root certificate into the Trusted Root CA Certificate store that’s valid until January 13, 2027, as well as an encrypted private key. The problem for Sennheiser is that the certificate uses the same decryption key for every installation of the software. An attacker who’s able to decrypt this key would be able to issue forged certificates that impersonate any HTTPS website. These new certificates would give attackers access to traffic for other domains, allowing hackers to perform man-in-the-middle attacks.

Recommended Videos

“We found that — caused by a critical implementation flaw — the secret signing key of one of the clandestine planted root certificates can be easily obtained by an attacker,” Secorvo noted in its report. “This allows him or her to sign and issue technically trustworthy certificates. Users affected by this implementation bug can become victim of such a certificate forgery, allowing an attacker to send [for example] trustworthy signed software, or acting as an authority authorized by Sennheiser.”

“With this in place, a hacker could effectively snoop on a persons’ traffic and read and alter the supposedly encrypted traffic to targeted domains,” The Inquirer noted of the danger of the HeadSetup vulnerability. “From there, information could be pilfered, such as data pertaining to log in to web services.”

As a result of Secorvo’s report, Microsoft has also issued security advisory ADV180029, warning users and system administrator that “inadvertently disclosed digital certificates could allow spoofing.” This type of vulnerability isn’t unlike the widely publicized Lenovo Superfish bug from 2015. In the Lenovo case, users became aware that pre-installed bloatware were signed with a weak security certificate that could allow hackers to inject malicious software on Lenovo systems or access data that would have otherwise been encrypted.

Sennheiser claims that is is working on an update to its HeadSetup software to patch the vulnerability. “Sennheiser was informed about this vulnerability in advance, is aware of the vulnerability impact, and started working on an updated version of HeadSetup to resolve the issue,” Secorvo wrote in its report. “According to the developers, this process will take a while.”

In the interim, Sennheiser has implemented a temporary fix to keep users protected by removing the certificate. Users can access the temporary solution through the headphone maker’s support site while the HeadSetup software is being updated.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
The Best Password Managers for 2026
As online security evolves, so should the way you protect your accounts
password manager on a mac.

Think about how many online accounts you use in a typical week. Between work, banking, shopping, streaming, social media, and everything in between, it's easy to end up managing dozens of passwords. Remembering a different, secure password for every account simply isn't realistic, which is why so many people fall back on reusing the same login across multiple websites. That's a recipe for disaster, if you ask any cybersecurity expert.

If you're in a conundrum on how to safely handle digital privacy, password managers are a reliable solution. Rather than trying to remember every single password yourself, a credentials manager tool securely stores your login details, creates stronger passwords for new accounts, and automatically fills them in whenever you need them.

Read more
Amazon and Walmart’s AI can spot fake ‘Made in USA’ labels but won’t tell you, says study
The same chatbot that happily discusses "Made in China" claims stays silent on "Made in USA" ones.
amazon-join-the-chat-ai

When you ask an AI shopping assistant to help you find products, you probably expect it to point out misleading listings too. According to a new study, both Amazon and Walmart's AI tools can detect fake "Made in USA" claims. However, the study claims that retailers are not using those capabilities to flag or remove the misleading listings, even when the AI recognizes conflicting information on the same product page.

How did the researchers catch this fraud?

Read more
Samsung lays out grim pricing prophecy for mobile and PC gear
Memory shortage could get worse in 2027 and last through 2028
Electronics, Phone, Mobile Phone

Samsung warned in April that the memory shortage could get worse in 2027. Three months later, the company’s outlook has become even more troubling for anyone planning to buy a new phone, laptop, gaming PC, or another device packed with memory and storage.

During its Q2 2026 earnings call, Samsung said demand is still running far ahead of supply and that orders it cannot fulfil this year are likely to spill into the next. The company now expects the shortage to persist through 2028, extending its earlier warning by another year.

Read more