# Apple Patches Critical Bluetooth Flaw in Beats Studio Buds That Could Enable Remote Eavesdropping


Apple has released urgent firmware updates to address a high-severity vulnerability in its Beats Studio Buds wireless earbuds that could allow nearby attackers to eavesdrop on users' conversations without requiring device pairing or authentication. The flaw, tracked as CVE-2025-20701, represents a critical gap in the Bluetooth authentication layer that researchers have demonstrated can be weaponized to fully compromise vulnerable devices.


The vulnerability was patched in Beats Firmware Update 1B211, which is being automatically delivered to affected headphones when they connect to paired iOS, iPad, or macOS devices. Users should verify that the patch has been applied through their Bluetooth settings.


## The Vulnerability: What's at Risk


The flaw affects the audio transmission and pairing mechanisms of Beats Studio Buds, specifically in the Bluetooth BR/EDR (Basic Rate/Enhanced Data Rate) radio implementation. According to Apple's official security advisory, the core issue is straightforward and dangerous: an attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired and actively seeking pair requests.


What makes this vulnerability particularly concerning is that it requires:

  • No authentication between the attacker and the device
  • No existing pairing relationship
  • No user interaction or awareness
  • Only Bluetooth range proximity (typically 30-240 feet depending on environmental factors)

  • The vulnerability was initially assigned the CVE identifier by a third party, and Apple confirmed that the affected code originated from an open-source project used across multiple software ecosystems—meaning similar vulnerabilities may exist in other products using the same underlying libraries.


    ## Technical Details: The Airoha SoC Weakness


    The vulnerability originates from the Airoha system-on-a-chip (SoC) used in the Beats Studio Buds. Security researchers Dennis Heinze and Frieder Steinmetz of ERNW GmbH discovered that the SoC's implementation of Bluetooth security lacks proper authentication mechanisms in the pairing handshake.


    The attack chain works as follows:


    1. An attacker initiates a Bluetooth connection request to a vulnerable Beats device

    2. The device accepts the connection request without verifying the attacker's identity

    3. The attacker can then access the microphone stream through the Hands-Free Profile (HFP)

    4. Once established, the attacker can listen to all audio input from the microphone


    ### Chained Vulnerabilities Amplify the Risk


    Researchers discovered that when CVE-2025-20701 is combined with two additional flaws (CVE-2025-20700 and CVE-2025-20702), the attack surface expands dramatically:


    | Vulnerability | Impact | Severity |

    |---|---|---|

    | CVE-2025-20701 | Unauthorized microphone access | High |

    | CVE-2025-20700 | Unauthorized command execution via Bluetooth | Critical |

    | CVE-2025-20702 | Memory access (RAM/flash read and write) | Critical |


    When chained together, these vulnerabilities enable attackers to:

  • Hijack Bluetooth connections between the phone and earbuds
  • Issue arbitrary commands to the paired smartphone via the Hands-Free Profile
  • Extract Bluetooth link keys from the device's memory
  • Access call history and contacts
  • Initiate calls to arbitrary numbers
  • Read currently playing media on the device
  • Achieve full device takeover through direct memory access

  • According to the ERNW researchers, "In most cases, these vulnerabilities allow attackers to fully take over the headphones via Bluetooth. No authentication or pairing is required. The vulnerabilities can be triggered via Bluetooth BR/EDR or Bluetooth Low Energy (BLE). Being in Bluetooth range is the only precondition."


    ## Background and Discovery: One Year from Disclosure to Patch


    The vulnerability was originally discovered and disclosed by ERNW GmbH researchers at the TROOPERS security conference in Germany approximately one year ago. The researchers presented their findings publicly, including a proof-of-concept exploit demonstrating that attackers could:


  • Initiate calls on a target device
  • Eavesdrop on conversations in real-time
  • Extract sensitive data stored on the device
  • Issue voice commands

  • The fact that Apple took a year to patch this vulnerability—despite public disclosure at a major security conference—raises questions about the company's vulnerability management timeline and the initial severity assessment. However, the delayed patch may have been driven by the need to coordinate with Airoha (the SoC manufacturer) and potentially with other affected vendors using the same chipset.


    ## Attack Complexity and Real-World Risk Assessment


    While the technical vulnerability is severe, the researchers noted important practical limitations:


    Real attacks are complex to perform, according to ERNW findings, and would likely be attempted only against high-value targets due to:


  • Technical sophistication required — Exploiting these vulnerabilities requires advanced Bluetooth protocol knowledge and custom tooling
  • Physical proximity requirement — Attackers must be within Bluetooth range (typically 30-240 feet, but can be extended with specialized equipment)
  • Target selection challenges — Identifying and distinguishing vulnerable devices in public spaces
  • Timing constraints — Attacks typically require the target device to be in pairing mode or actively seeking connections

  • However, the low barrier to entry for technically skilled attackers and the absence of any authentication layer means that:

  • Nation-state actors could easily develop weaponized exploits
  • Corporate espionage operations could target executives and high-value employees
  • Sophisticated cybercriminals could focus on affluent individuals carrying expensive Apple devices
  • The vulnerability creates a passive attack vector in public spaces (airports, corporate offices, conference centers) where multiple potential targets cluster

  • ## How to Verify and Apply the Patch


    Users can verify whether their Beats Studio Buds have been patched by:


    1. On iPhone or iPad: Open Settings → Bluetooth

    2. Locate your Beats Studio Buds in the list of connected devices

    3. Tap the information icon (ⓘ) next to the device name

    4. Check the Firmware Version — it should display 1B211 or later


    Automatic patch deployment:

  • Apple is delivering Beats Firmware Update 1B211 automatically when vulnerable headphones are paired and within Bluetooth range of an iPhone, iPad, or Mac running current software
  • No manual action is required for most users, but verification is recommended
  • Users with older devices or those with Bluetooth connectivity issues may need to manually trigger the update by re-pairing the headphones

  • ## Implications for Users and Organizations


    For Individual Users:

  • Immediate risk is low for general users unless they are targeted by sophisticated attackers
  • Higher risk for business executives, journalists, government officials, and others who might be targeted
  • Passive eavesdropping represents the primary threat vector — conversation interception in public spaces

  • For Organizations:

  • Executive protection teams should audit Beats devices and ensure firmware is current
  • Sensitive conversation environments (boardrooms, offices) may warrant additional security controls
  • BYOD policies should require device firmware updates as a condition of network access
  • Incident response teams should consider whether Beats device compromise could indicate APT activity

  • For Enterprise Security Teams:

  • Monitor for unusual Bluetooth activity and unauthorized device connections
  • Audit device inventory for Beats products and enforce mandatory firmware updates
  • Consider implementing Bluetooth range detection in physically secure areas
  • Review Bluetooth security posture across all wireless devices, as similar vulnerabilities may exist in competing products

  • ## Recommendations


    For Users:

  • ✓ Verify your Beats Studio Buds firmware is updated to version 1B211 or later
  • ✓ Ensure your paired iPhone, iPad, or Mac is running the latest OS version to enable automatic updates
  • ✓ If you haven't used the headphones recently, pair them to a device running current software to trigger the firmware update
  • ✓ Consider disabling Bluetooth when not in use, particularly in public spaces
  • ✓ Avoid discussing sensitive information while wearing wireless earbuds in public

  • For Organizations:

  • ✓ Audit inventory for Beats and similar wireless audio devices
  • ✓ Include firmware verification in mobile device management (MDM) policies
  • ✓ Brief executive protection and sensitive personnel about the vulnerability timeline
  • ✓ Review Bluetooth security settings on corporate networks and access points
  • ✓ Evaluate alternative wireless audio solutions with more robust security implementations
  • ✓ Conduct risk assessments for roles and individuals who might be targeted by sophisticated attackers

  • ---


    ## HackWire Analysis


    This vulnerability illustrates a pattern increasingly visible in consumer security: hardware manufacturers are shipping wireless devices without fundamental security controls, then taking months or years to patch when those gaps are discovered. The fact that Apple took a full year after public disclosure at a major conference to patch this flaw—and that the vulnerability required researchers to demonstrate practical exploits before action was taken—suggests that vulnerability response timelines in consumer audio are unacceptably long.


    What's particularly striking is the chaining mechanism: individually, CVE-2025-20701 enables eavesdropping; combined with the two companion flaws, it becomes a complete device compromise. This is a reminder that Bluetooth security overall remains immature—protocols were designed in the early 2000s with threat models that didn't account for sophistication of modern attacks.


    The practical limiting factor here—that "real attacks are complex to perform"—is precisely the kind of false comfort that protects vulnerabilities from patching. Complexity is no defense against determined adversaries. A nation-state, organized crime ring, or corporate espionage operation will absolutely develop tooling to exploit this at scale. The researchers demonstrated proof-of-concept attacks; weaponization is trivial from that point.


    The real takeaway for enterprises: Stop assuming wireless audio devices are low-security peripherals. They sit at the boundary between physical and digital security, and they're increasingly part of threat models for high-value targets. Firmware visibility and update enforcement for wireless devices should be as mandatory as it is for routers and VPNs.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)