# Apple Patches Critical Bluetooth Flaw in Beats Studio Buds That Could Enable Remote Eavesdropping
Apple has released urgent firmware updates to address a high-severity vulnerability in its Beats Studio Buds wireless earbuds that could allow nearby attackers to eavesdrop on users' conversations without requiring device pairing or authentication. The flaw, tracked as CVE-2025-20701, represents a critical gap in the Bluetooth authentication layer that researchers have demonstrated can be weaponized to fully compromise vulnerable devices.
The vulnerability was patched in Beats Firmware Update 1B211, which is being automatically delivered to affected headphones when they connect to paired iOS, iPad, or macOS devices. Users should verify that the patch has been applied through their Bluetooth settings.
## The Vulnerability: What's at Risk
The flaw affects the audio transmission and pairing mechanisms of Beats Studio Buds, specifically in the Bluetooth BR/EDR (Basic Rate/Enhanced Data Rate) radio implementation. According to Apple's official security advisory, the core issue is straightforward and dangerous: an attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired and actively seeking pair requests.
What makes this vulnerability particularly concerning is that it requires:
The vulnerability was initially assigned the CVE identifier by a third party, and Apple confirmed that the affected code originated from an open-source project used across multiple software ecosystems—meaning similar vulnerabilities may exist in other products using the same underlying libraries.
## Technical Details: The Airoha SoC Weakness
The vulnerability originates from the Airoha system-on-a-chip (SoC) used in the Beats Studio Buds. Security researchers Dennis Heinze and Frieder Steinmetz of ERNW GmbH discovered that the SoC's implementation of Bluetooth security lacks proper authentication mechanisms in the pairing handshake.
The attack chain works as follows:
1. An attacker initiates a Bluetooth connection request to a vulnerable Beats device
2. The device accepts the connection request without verifying the attacker's identity
3. The attacker can then access the microphone stream through the Hands-Free Profile (HFP)
4. Once established, the attacker can listen to all audio input from the microphone
### Chained Vulnerabilities Amplify the Risk
Researchers discovered that when CVE-2025-20701 is combined with two additional flaws (CVE-2025-20700 and CVE-2025-20702), the attack surface expands dramatically:
| Vulnerability | Impact | Severity |
|---|---|---|
| CVE-2025-20701 | Unauthorized microphone access | High |
| CVE-2025-20700 | Unauthorized command execution via Bluetooth | Critical |
| CVE-2025-20702 | Memory access (RAM/flash read and write) | Critical |
When chained together, these vulnerabilities enable attackers to:
According to the ERNW researchers, "In most cases, these vulnerabilities allow attackers to fully take over the headphones via Bluetooth. No authentication or pairing is required. The vulnerabilities can be triggered via Bluetooth BR/EDR or Bluetooth Low Energy (BLE). Being in Bluetooth range is the only precondition."
## Background and Discovery: One Year from Disclosure to Patch
The vulnerability was originally discovered and disclosed by ERNW GmbH researchers at the TROOPERS security conference in Germany approximately one year ago. The researchers presented their findings publicly, including a proof-of-concept exploit demonstrating that attackers could:
The fact that Apple took a year to patch this vulnerability—despite public disclosure at a major security conference—raises questions about the company's vulnerability management timeline and the initial severity assessment. However, the delayed patch may have been driven by the need to coordinate with Airoha (the SoC manufacturer) and potentially with other affected vendors using the same chipset.
## Attack Complexity and Real-World Risk Assessment
While the technical vulnerability is severe, the researchers noted important practical limitations:
Real attacks are complex to perform, according to ERNW findings, and would likely be attempted only against high-value targets due to:
However, the low barrier to entry for technically skilled attackers and the absence of any authentication layer means that:
## How to Verify and Apply the Patch
Users can verify whether their Beats Studio Buds have been patched by:
1. On iPhone or iPad: Open Settings → Bluetooth
2. Locate your Beats Studio Buds in the list of connected devices
3. Tap the information icon (ⓘ) next to the device name
4. Check the Firmware Version — it should display 1B211 or later
Automatic patch deployment:
## Implications for Users and Organizations
For Individual Users:
For Organizations:
For Enterprise Security Teams:
## Recommendations
For Users:
For Organizations:
---
## HackWire Analysis
This vulnerability illustrates a pattern increasingly visible in consumer security: hardware manufacturers are shipping wireless devices without fundamental security controls, then taking months or years to patch when those gaps are discovered. The fact that Apple took a full year after public disclosure at a major conference to patch this flaw—and that the vulnerability required researchers to demonstrate practical exploits before action was taken—suggests that vulnerability response timelines in consumer audio are unacceptably long.
What's particularly striking is the chaining mechanism: individually, CVE-2025-20701 enables eavesdropping; combined with the two companion flaws, it becomes a complete device compromise. This is a reminder that Bluetooth security overall remains immature—protocols were designed in the early 2000s with threat models that didn't account for sophistication of modern attacks.
The practical limiting factor here—that "real attacks are complex to perform"—is precisely the kind of false comfort that protects vulnerabilities from patching. Complexity is no defense against determined adversaries. A nation-state, organized crime ring, or corporate espionage operation will absolutely develop tooling to exploit this at scale. The researchers demonstrated proof-of-concept attacks; weaponization is trivial from that point.
The real takeaway for enterprises: Stop assuming wireless audio devices are low-security peripherals. They sit at the boundary between physical and digital security, and they're increasingly part of threat models for high-value targets. Firmware visibility and update enforcement for wireless devices should be as mandatory as it is for routers and VPNs.
— HackWire Editorial
---
## Related Coverage