Australians using some low-cost AI-enabled smart glasses have been warned about serious security vulnerabilities that could allow attackers to access personal information stored on the devices.

An investigation published on September 22 found that independent cybersecurity testing identified multiple weaknesses in smart glasses and their associated mobile application. Researchers found that some devices could potentially be accessed through Bluetooth without requiring a password.

The testing examined inexpensive smart glasses available to Australian consumers. Researchers found that an attacker who was nearby could potentially connect to an unpaired device and gain control of some of its functions.

Once access was obtained, researchers said an attacker could potentially take photographs and recordings through the glasses and access images or videos already stored on the device.

The investigation also identified vulnerabilities involving the communication between the glasses, the mobile application and online services. Researchers found that information could potentially be intercepted while being transferred between devices.

Another concern involved device identification information. Researchers said information exposed through Bluetooth could potentially be combined with weaknesses in the associated website to reveal personal details such as an email address and date of birth.

The findings have raised questions about the security standards applied to inexpensive connected devices before they reach Australian consumers.

Privacy concerns surrounding smart glasses have already increased in several Australian cities because the devices can record images, video and audio while appearing similar to ordinary sunglasses.

Councils in cities including Brisbane and Melbourne's Yarra municipality have introduced restrictions on the use of camera-enabled smart glasses in some public facilities. These measures have focused particularly on locations such as swimming pools, gyms, childcare facilities and other places where people may reasonably expect a higher level of privacy.

The new security findings add another dimension to those concerns. Instead of only considering whether a wearer could secretly record another person, cybersecurity researchers are warning that the wearer could also potentially become a target if the device itself is inadequately protected.

Testing also raised questions about where information collected by some smart-glasses applications is processed and stored. Researchers identified overseas servers being used for some functions, although the testing did not establish exactly how all collected information was ultimately used.

At least one Australian supplier has reportedly stopped selling one affected range following concerns about the security findings.

The investigation has highlighted the importance of checking the privacy and security arrangements of connected consumer devices before using them to record photographs, videos or conversations.

Consumers who already own similar devices may wish to check whether manufacturers or retailers have released security updates and review the permissions granted to the associated mobile application.

The findings relate to specific products and testing conditions and should not automatically be applied to every smart-glasses product available in Australia.