9To5Mac
Critical Bluetooth Vulnerability in Beats Earbuds Allows Eavesdropping
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A serious security vulnerability has been discovered in Apple's Beats Studio Buds, allowing attackers within Bluetooth range to eavesdrop through the device's microphone. The flaw, identified as CVE-2025-20701, is linked to an open-source Airoha Bluetooth Audio SDK used in the earbuds. For exploitation, the earbuds must be unpaired and actively searching for connections. Apple has released firmware version 1B211 to address this issue, which was reported by security researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH. The vulnerability was known since mid-2025 but was only patched in June 2026. Users are advised to ensure their devices are updated to the latest firmware to mitigate the risk. The vulnerability also affects other earbuds using the same SDK, not just Beats products.
Key Points: • A Bluetooth vulnerability in Beats Studio Buds allows eavesdropping via the microphone. • The flaw is tracked as CVE-2025-20701 and was discovered by ERNW GmbH researchers. • Apple has released firmware version 1B211 to fix the vulnerability, which users must manually ensure is installed.