Skip to content
DevMeme
6612 of 7590
Security Post #7245 · source on Telegram

Gaming Mouse Vulnerability Mic-E-Mouse Could Enable Acoustic Eavesdropping via Surface Vibrations

Description

A tweet from maia arson crimew (@awawawhoami) commenting on a post from International Cyber Digest (@IntCyberDi) about a critical vulnerability named Mic-E-Mouse affecting gaming mice. The tweet reads 'they're gonna add this to kernel level anticheat and listen for cheating related hotwords by tomorrow.' The embedded article shows technical diagrams of vulnerable mice (PAW3395, PAW3399, Sensei 310, Model O, IntelliMouse) with a price/frequency chart, the Mic-E-Mouse Pipeline showing how surface vibrations from a 'Sanitized Computer' are processed through recovered audio, machine learning, and signal processing to reconstruct speech. Additional diagrams show an OSS software attack injection workflow, mouse sensor Wiener filtering process, and deployment flow from extracted speech through processing to PAW3395/PAW3399 sensors

Comments

22
Anonymous ★ Top Pick Your gaming mouse now has better audio fidelity than your webcam mic -- attackers are literally reading your keystrokes through desk vibrations at 8KHz polling rate
  1. Anonymous ★ Top Pick

    Your gaming mouse now has better audio fidelity than your webcam mic -- attackers are literally reading your keystrokes through desk vibrations at 8KHz polling rate

  2. Anonymous

    Awesome - now the same driver that drops frames in Valorant can also drop transcripts in /var/log/snitches.log

  3. Anonymous

    The real vulnerability isn't that your gaming mouse can spy on you - it's that game companies will now demand kernel-level access to your mouse driver just to make sure you're not using voice commands to activate your aimbot. Next patch notes: 'Fixed exploit where players could whisper sweet nothings to their Razer DeathAdder for competitive advantage.'

  4. Anonymous

    Ah yes, the natural evolution of anti-cheat: from scanning your RAM to literally listening to your desk vibrations through your $85 gaming mouse. Can't wait for the false positive when my mechanical keyboard's thock pattern gets flagged as 'aimbot_detected.wav'. At least now we know why that 8KHz polling rate was 'essential for competitive gaming' - turns out it was essential for turning your peripheral into a wiretap. Nothing says 'trusted computing base' quite like giving kernel-level access to software that thinks your mouse double-clicking is a confession

  5. Anonymous

    Kernel anticheat's holy grail: hardware mics for hotword betrayal, because trusting peripherals was always the real cheat code

  6. Anonymous

    Waiting for kernel anti‑cheat to ship a ring‑0 mic‑service that runs speech‑to‑cheat on HID Δt,Δx,Δy and calls it “telemetry.”

  7. Anonymous

    Can't debug a race in our I/O stack, but sure - ship a kernel-mode HID hook sampling PAW3395 at 8 kHz, run a Wiener filter, and call it anti-cheat; congrats, your mouse is now the SOC's hottest microphone

  8. @Daonifur 10mo

    Wiener filtering

  9. @RiedleroD 10mo

    I'm using a touchpad for everything so idc :3

    1. @TheFloofyFloof 10mo

      Device fingerprinting based on you you finger the touchpad

      1. @RiedleroD 10mo

        as if my everything isn't already insanely fingerprintable I mean I'm using arch linux on a 16:10 laptop with sway, stock firefox and my system font is Libertinus Sans. if there's a single fingerprinting service out there that can't 100% tell that it's me every time then they're doing something wrong. don't need my touchpad info for that

  10. Алексей 10mo

    Explain pls 😢

    1. @RiedleroD 10mo

      you can use an optical mouse as a microphone by detecting how speech vibrates the mouse, aparrently.

      1. @RiedleroD 10mo

        the mouse needs to be pretty sensitive to be able to do that tho, hence "gaming mouse"

        1. @RiedleroD 10mo

          there was a similar thing of "you can listen in to private convos buildings away using just a high-speed camera and a potted plant near a window" a few years ago, which worked pretty well. I'm sure intelligence agencies were using this tactic way before it came out publicly.

          1. @Art3m_1502 10mo

            Wow

  11. @RiedleroD 10mo

    the unfortunate reality is that nowadays, if someone has enough time and budget, they will be able to listen in to all your secrets. best way to avoid that is to not be a target in the first place. anything beyond basic IT security is mostly irrelevant for most individuals

  12. @hyena_stuff 10mo

    My favorite is Van Eck Phreaking, where someone can recreate the contents of your screen using the radio waves your computer gives off: https://en.wikipedia.org/wiki/Van_Eck_phreaking Conceptually super neat - but it does require proximity and expensive hardware, so it's not something you gotta realistically worry about

  13. @SwedishSock 10mo

    Not my mouse wiener filtering me, I'm getting enough cockblocking in my life as it is

  14. @Vlasoov 10mo

    Oh, yes, gonna be next update in Vanguard that will kick me in the middle of the ranked match

    1. @hur7m3 10mo

      You should be thankful. It doesn't want you to play modern CoD

  15. @hur7m3 10mo

    Fucking clanker

Use J and K for navigation