First published: Tue May 02 2023(Updated: )
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 5E133. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.
Credit: product-security@apple.com Yun-hao Chung Archie Pusaka Google ChromeOS
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Beats Firmware Update B66 | <5 | 5 |
Apple AirPods Firmware | =5e133 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27964 is classified as a medium-severity authentication issue.
To fix CVE-2023-27964, update your AirPods to Firmware Update 5E133 or Beats to Firmware Update B66.
CVE-2023-27964 affects AirPods with firmware version 5E133 and Beats firmware version B66 or earlier.
CVE-2023-27964 enables attackers to spoof the intended source device during a Bluetooth connection request.
It is recommended to promptly update your devices to the latest firmware to mitigate the risk associated with CVE-2023-27964.