CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Apple Patches Beats Studio Buds Flaw Allowing Nearby Attackers to Spy via Microphone

June 25, 2026

Apple has released a firmware update for Beats Studio Buds wireless earbuds to address a high-severity vulnerability, CVE-2025-20701 (CVSS 8.8), that could allow nearby attackers to eavesdrop on users via the microphone. The flaw stems from incorrect authorization in the Airoha Bluetooth audio SDK, enabling unauthorized Bluetooth pairing without user consent. Successful exploitation leads to remote escalation of privilege with no user interaction required. The issue is fixed in Beats Firmware Update 1B211.

Originally disclosed in June 2025 by ERNW GmbH researchers Dennis Heinze and Frieder Steinmetz at the TROOPERS security conference, the vulnerability was part of a trio of flaws in Airoha SoCs (CVE-2025-20700, CVE-2025-20701, CVE-2025-20702). Jabra released similar patches in December 2025. The researchers noted that attackers within Bluetooth range could fully take over headphones without authentication, reading and writing device RAM and flash, and potentially hijacking trusted relationships with paired devices.

Separately, Paradigm Shift disclosed a novel BootROM vulnerability (usbliter8) affecting Apple’s A12 and A13 chips. This exploit leverages a hardware bug in the USB controller and a configuration flaw in device firmware, allowing malicious code injection and execution. As the vulnerability resides in immutable code, migrating to newer hardware is the only effective mitigation. The usbliter8 exploit is comparable to the checkm8 exploit but affects newer SecureROM generations, including those with Pointer Authentication.

CVEs: CVE-2025-20701, CVE-2025-20700, CVE-2025-20702, CVE-2026-11645

Companies: Apple, ERNW GmbH, Paradigm Shift, Jabra

Products: Beats Studio Buds, Airoha Bluetooth audio SDK, Airoha SoCs, A12 chip, A13 chip

Events: TROOPERS