Back to News
Vulnerabilities

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Cyber RTJune 19, 20263 min read
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has updated its Beats Studio Buds to fix a high-severity vulnerability (CVE-2025-20701) that allowed unauthorized Bluetooth pairing, enabling eavesdropping. The flaw, impacting Airoha Bluetooth audio SDK, was patched in Beats Firmware Update 1B211. Additionally, Paradigm Shift disclosed a BootROM vulnerability affecting Apple's A12 and A13 chips, allowing code execution via a USB controller flaw. Users are advised to upgrade hardware for mitigation.

Apple has recently addressed a significant security vulnerability in its Beats Studio Buds wireless earbuds. This vulnerability, identified as CVE-2025-20701 with a CVSS score of 8.8, was found in the Airoha Bluetooth audio SDK. It allowed unauthorized pairing of Bluetooth audio devices, potentially enabling hackers within Bluetooth range to eavesdrop on users. The flaw has been rectified with the release of Beats Firmware Update 1B211, which prevents unauthorized access to the device's microphone. The vulnerability was initially discovered by researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH. They presented their findings at the TROOPERS security conference in Germany in June 2025, highlighting the potential for remote privilege escalation without user interaction. Alongside this vulnerability, two other flaws in Airoha SoCs were also identified. In response, similar patches were released by Jabra in December 2025 to address these issues. The researchers noted that these vulnerabilities could allow attackers to fully control the headphones via Bluetooth, without requiring authentication or pairing. The attack could be executed using Bluetooth BR/EDR or Bluetooth Low Energy (BLE), with the only requirement being proximity to the target device. This capability could enable attackers to hijack trust relationships with other paired devices, such as smartphones. In a related development, Paradigm Shift, a European cybersecurity company, disclosed a new vulnerability in Apple's A12 and A13 chips. This vulnerability, found in the iPhone SecureROM (BootROM), is exploited using a proof-of-concept called usbliter8. The exploit takes advantage of a hardware bug in the USB controller and a firmware configuration flaw, allowing for malicious code injection and execution. The exploit operates by leveraging a flaw in the USB controller's memory buffer, which stores SETUP and OUT packets during data transfer. By exploiting this buffer underflow, attackers can inject and execute malicious code. The vulnerability is inherent to the hardware of the USB controller in A12 and A13 chips, making it unpatchable through software updates. The A11 chip is not affected due to different USB driver configurations. Paradigm Shift explained that the A11 USB driver resets the DMA address after each packet, preventing exploitation. However, on A12 and A13 chips, the USB DART is in bypass mode, allowing SRAM data to be overwritten. Later chip generations, starting from A14, have corrected this configuration in SecureROM, rendering the vulnerability unexploitable. The usbliter8 exploit is similar to the checkm8 exploit, which affected earlier iOS devices. Despite advancements in SecureROM generations, including Pointer Authentication, subtle hardware bugs like those exploited by usbliter8 can still compromise device security. Although usbliter8 does not directly affect the Secure Enclave Processor (SEP), it opens up broader attack vectors, potentially compromising the device's Secure Enclave.