• News/
  • bleepingcomputer-20260618122358

Apple fixes Beats Studio Buds flaw that let hackers spy on conversations

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 18, 2026
·
Updated

Apple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluetooth range to spy on users' conversations. "An attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired and actively seeking pair requests," Apple explained in a Tuesday advisory. "This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party." Apple patched the vulnerability in Beats Firmware Update 1B211, which will be automatically delivered to vulnerable headphones when they are paired and within Bluetooth range of the user's iPhone, iPad, or Mac. You can check whether the firmware has been applied from the Bluetooth settings on your device by tapping the info button next to the headphones. The security flaw (CVE-2025-20701) was discovered by Dennis Heinze and Frieder Steinmetz of ERNW GmbH in the Airoha system-on-a-chip (SoCs). When they disclosed the vulnerability one year ago at the TROOPERS security conference in Germany, the ERNW security researchers said that it stems from a missing authentication weakness in the Bluetooth BR/EDR radio. They also created a proof-of-concept exploit that allows attackers to initiate a call and eavesdrop on conversations within earshot of the targeted phone. When chaining CVE-2025-20701 with two other vulnerabilities (tracked as CVE-2025-20700 and CVE-2025-207...

Read full article

Affected Software

2 affected components
Apple Beats Studio Buds<1B211
Airoha Airoha SoC firmware
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security flaw in the Apple Beats Studio Buds that allows hackers to spy on conversations.

2

What security implications are discussed in the article?

The article highlights the risk of unauthorized access to the microphone, enabling attackers to eavesdrop on users within Bluetooth range.

3

What products or software are affected by the flaw?

The affected products include Apple Beats Studio Buds and Airoha System-on-Chip (SoC) firmware.

4

How did Apple address the vulnerability?

Apple released security updates to patch the high-severity flaw in the Beats Studio Buds.

5

What is the significance of this vulnerability being KEV-listed?

Being KEV-listed indicates that this vulnerability is recognized as a known exploited vulnerability, which raises its priority for patching and awareness.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203