Critical Bluetooth Vulnerability in Beats Earbuds Allows Eavesdropping

Critical Bluetooth Vulnerability in Beats Earbuds Allows Eavesdropping

First seen 17 Jun 2026, 17:10 UTC Macrumors9To5MacIphoneincanada.CaHeise.Denvd.nist.gov+20 92% similarity 72.0

Article Content

Browse articles
ThreatCluster

A serious security vulnerability has been discovered in Apple's Beats Studio Buds, allowing attackers within Bluetooth range to eavesdrop through the device's microphone. The flaw, identified as CVE-2025-20701, is linked to an open-source Airoha Bluetooth Audio SDK used in the earbuds. For exploitation, the earbuds must be unpaired and actively searching for connections. Apple has released firmware version 1B211 to address this issue, which was reported by security researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH. The vulnerability was known since mid-2025 but was only patched in June 2026. Users are advised to ensure their devices are updated to the latest firmware to mitigate the risk. The vulnerability also affects other earbuds using the same SDK, not just Beats products.

Key Points: • A Bluetooth vulnerability in Beats Studio Buds allows eavesdropping via the microphone. • The flaw is tracked as CVE-2025-20701 and was discovered by ERNW GmbH researchers. • Apple has released firmware version 1B211 to fix the vulnerability, which users must manually ensure is installed.

ThreatCluster AI How this analysis works

Timeline

2025-06-01
Vulnerability discovered
Security researchers from ERNW GmbH identified the eavesdropping flaw in Beats Studio Buds.
Heise.De
2025-08-04
CVE-2025-20701 published
A vulnerability in the Airoha Bluetooth audio SDK allows unauthorized microphone access.
NVD
2026-06-16
Firmware update released
Apple released firmware version 1B211 to patch the critical vulnerability in Beats Studio Buds.
9To5Mac
Recent
Public awareness raised
Media outlets began reporting on the vulnerability and the importance of updating the firmware.
Iphoneincanada.Ca

Community

Browse all →