Vulnerabilities affecting a Bluetooth chipset present in more than two dozen audio devices from ten vendors can be exploited for eavesdropping or stealing sensitive information. Researchers confirmed that 29 devices from Beyerdynamic, Bose, Sony, Marshall, Jabra, JBL, Jlab, EarisMax, MoerLabs, and Teufel are affected. The list of impacted products includes speakers, earbuds, headphones, and wireless microphones. The security problems could be leveraged to take over a vulnerable product and on some phones, an attacker within connection range may be able to extract call history and contacts. At the TROOPERS security conference in Germany, researchers at cybersecurity company ERNW disclosed three vulnerabilities in the Airoha systems on a chip (SoCs), which are widely used in True Wireless Stereo (TWS) earbuds. The issues are not critical and besides close physical proximity (Bluetooth range), their exploitation also requires “a high technical skill set.” They received the following identifiers: ERNW researchers say they created a proof-of-concept exploit code that allowed them to read the currently playing media from the targeted headphones. While such an attack may not present a great risk, other scenarios leveraging the three bugs could let a threat actor hijack the connection between the mobile phone and an audio Bluetooth device and use the Bluetooth Hands-Free Profile (HFP) to issue commands to the phone. “The range of available commands depends on the mobile operating sy...
Bluetooth flaws could let hackers spy through your microphone
BleepingComputer
·Ionut Ilascu
·Published Jun 29, 2025
·Updated
Affected Software
10 affected components
Beyerdynamic audio device
Bose audio device
Sony audio device
Marshall audio device
Jabra audio device
JBL audio device
Jlab audio device
EarisMax audio device
MoerLabs audio device
Teufel audio device
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses security vulnerabilities in Bluetooth chipsets that could allow hackers to eavesdrop through microphones in affected audio devices.
2
What security implications are discussed?
The vulnerabilities could enable unauthorized access to sensitive information by allowing hackers to listen in on conversations via compromised audio devices.
3
What products or software are affected?
The flaws affect audio devices from multiple vendors including Beyerdynamic, Bose, Sony, Marshall, Jabra, JBL, Jlab, EarisMax, MoerLabs, and Teufel.
4
How many devices are confirmed to be vulnerable?
Researchers have confirmed that 29 different devices are vulnerable due to the Bluetooth chipset flaws.
5
What action should users take regarding these vulnerabilities?
Users are advised to check for firmware updates from their device manufacturers to mitigate the potential risks associated with these Bluetooth flaws.