Vulnerabilities · 87 days ago

Beats Buds Stay Vulnerable Until They Reconnect

The fix is only real once the earbuds come back into range of an Apple device. A patched firmware exists, but Beats Studio Buds that are unpaired, idle, or offline can sit on the old code until they reconnect, so a simple "vendor patched it" read misses the delay.

Apple says Beats Firmware Update 1B211 fixes CVE-2025-20701. The flaw affects Beats Studio Buds and can let a nearby attacker listen through the microphone before pairing is complete; Apple says the update is delivered automatically when the buds are paired and within Bluetooth range of an iPhone, iPad, or Mac.

CVE-2025-20701

NVD KEV

CVSS 8.8 HIGH: in the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. EPSS 9% (95th percentile).

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-19

Editions

Related stories