Apple Patches Beats Studio Buds Flaw Rated 8.8 That Could Let Nearby Attackers Listen Through Microphone
Firmware version 1B211 fixes CVE-2025-20701 in Apple's Beats Studio Buds wireless earbuds, a vulnerability that could let a nearby attacker listen through the microphone while the device was not yet paired and seeking pairing requests.
The issue, rated 8.8 on the Common Vulnerability Scoring System, was described as incorrect authorization in the Airoha Bluetooth audio software development kit that could allow pairing without user consent and remote escalation of privilege without additional execution privileges or user interaction.
From the sources (2 posts)
@breachbrief📢Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that ma
@thehackersnews⚠️ Apple fixed a Beats Studio Buds bug (CVE-2025-20701) that could let a nearby attacker listen through the microphone when the device was not yet paired and seeking pair requests. Update to firmware 1B211. Read the full story: https://t.