Developer Tools

Your Beats Studio Buds Could Have Been Eavesdropped On — Why Apple's Urgent Patch Matters

CVE-2025-20701 scores 8.8, letting nearby attackers listen through unpaired earbuds.

Deep Dive

Apple has patched a high-severity vulnerability (CVE-2025-20701, CVSS 8.8) in its Beats Studio Buds wireless earbuds that could allow nearby attackers to eavesdrop on users. The flaw, disclosed by researchers Dennis Heinze and Frieder Steinmetz of security firm Insinuator, resides in the authentication mechanism of Bluetooth chips manufactured by Airoha Systems. Attackers within Bluetooth range could impersonate previously paired devices, gaining unauthorized access to the microphone without the user's knowledge. The researchers demonstrated end-to-end attacks that enabled real-time listening to conversations or ambient sounds.

The fix is delivered automatically via Beats Firmware Update 1B211 when the earbuds are paired with an iPhone, iPad, or Mac. Apple's advisory notes that vulnerable devices are those "not yet paired and actively seeking pair requests." The same week, Jabra also announced patches for affected devices, while Bose and JBL confirmed their products have been updated. The researchers also warned that the Airoha vulnerability chain could potentially allow attackers to retrieve call history, contacts, or even call arbitrary numbers, depending on the paired device platform. This disclosure follows closely on the heels of the "WhisperPair" vulnerabilities in Google Fast Pair, affecting devices from Sony, Nothing, OnePlus, and others. Although no active exploits have been reported in the wild, the high complexity and requirement for constant proximity limit practical attack scenarios.

Key Points
  • CVE-2025-20701 has a severity rating of 8.8/10 and allows attackers within Bluetooth range to eavesdrop through unpaired Beats Studio Buds.
  • The flaw originates from improper authentication in Airoha Systems chips; Apple's fix (firmware 1B211) updates automatically when paired with iOS/macOS devices.
  • Researchers also demonstrated capabilities like retrieving call history and calling arbitrary numbers on some paired devices.

Why It Matters

This attack undermines Bluetooth trust models, putting sensitive conversations at risk—patch immediately to prevent eavesdropping.

📬 Get the top 10 AI stories daily