CVE-2025-20701
CVSS 8.8 HIGH: in the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. EPSS 9% (95th percentile).
Vulnerabilities · 87 days ago
The fix is only real once the earbuds come back into range of an Apple device. A patched firmware exists, but Beats Studio Buds that are unpaired, idle, or offline can sit on the old code until they reconnect, so a simple "vendor patched it" read misses the delay.
Apple says Beats Firmware Update 1B211 fixes CVE-2025-20701. The flaw affects Beats Studio Buds and can let a nearby attacker listen through the microphone before pairing is complete; Apple says the update is delivered automatically when the buds are paired and within Bluetooth range of an iPhone, iPad, or Mac.
CVSS 8.8 HIGH: in the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. EPSS 9% (95th percentile).
3 sources covering this story
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
Apple fixed CVE-2025-20701 in Beats Studio Buds firmware 1B211, closing a Bluetooth pairing flaw that could allow nearby eavesdropping via Airoha SDK.
Apple patches eavesdropping vulnerability in Beats Studio Buds
The vulnerability, disclosed 12 months ago, affects multiple manufacturers.
Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
Apple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluetooth range to spy on users' conversations.
Part of the PlainSec briefing for 2026-06-19