logo

Heels on fire. Hacking smart ski socks

ID: 2a606bd9-907e-59df-99fc-04ea0045e6fd

STIX ID: report--2a606bd9-907e-59df-99fc-04ea0045e6fd

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-12-23

Date Updated: 2026-03-24

Author: Ken Munro

...
...

The report assesses Therm-IC smart heated ski socks and finds a BLE security flaw: the power packs are always pairable without bonding or an explicit pairing mode, allowing anyone in Bluetooth range to connect and turn up the heat when the owner’s phone is out of range; the authors demonstrate this and suggest potential (yet unconfirmed) arbitrary code execution on the battery controller for a future post, while judging real-world risk as low.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.