
What Happened
On June 16, 2026, Apple quietly released Beats Firmware Update 1B211 — a security patch for its Beats Studio Buds wireless earbuds. The update addresses a high-severity vulnerability that could have allowed an attacker sitting nearby to listen through the earbuds’ microphone without ever pairing with the device.
The vulnerability, tracked as CVE-2025-20701, was originally discovered and disclosed by security researchers Dennis Heinze and Frieder Steinmetz of the German cybersecurity firm ERNW GmbH. They first presented their findings at the TROOPERS security conference in June 2025 — which means Apple’s patch arrived a full twelve months after the vulnerability was first publicly known.
In that twelve-month window, every pair of Beats Studio Buds in pairing mode — in offices, coffee shops, airports, and conference rooms around the world — was potentially exposed.

The Root Cause: The Airoha RACE Protocol
To understand why this happened, you need to understand Airoha Technology — a subsidiary of MediaTek and one of the largest suppliers of Bluetooth System-on-Chips (SoCs) in the consumer audio market. Airoha chips power earbuds and headphones from dozens of the world’s most recognized audio brands.
What ERNW researchers discovered was that Airoha’s chips expose a powerful custom debug protocol called RACE (Remote Access Control Engine) over two separate Bluetooth interfaces — and crucially, neither of them required authentication
Security researchers at ERNW GmbH found that Airoha’s Bluetooth chips expose a powerful debug protocol without any authentication — silently accessible by anyone within Bluetooth range.
The RACE protocol was designed as a debugging and control interface during manufacturing and development. The problem: Airoha left it fully active and completely unauthenticated in consumer devices shipping to millions of customers. Any attacker within Bluetooth range could access it — no pairing, no credentials, no interaction from the device owner required.
The Three CVEs: What Each Flaw Does

Individually, each CVE is serious. When chained together, they enable a complete device takeover — and an attack chain that goes far beyond just listening through a microphone.
How the Attack Works: Step by Step
ERNW researchers built and demonstrated a working proof-of-concept. Here is exactly what an attacker in Bluetooth range can do:
- Connect Silently
The attacker’s device discovers earbuds in pairing mode and connects via BLE or Bluetooth Classic — completely silently, with no notification to the device owner. No pairing prompt appears. The owner has no idea anyone has connected.
Exploits: CVE-2025-20700 (BLE) or CVE-2025-20701 (Classic) - Access the Microphone
Using the Hands-Free Profile (HFP) available over the unauthenticated Classic Bluetooth connection, the attacker initiates a two-way audio connection and begins receiving live audio from the earbuds’ microphone — capturing ambient conversations, calls, and sensitive discussions.
Exploits: CVE-2025-20701 + HFP Bluetooth profile - Dump Flash Memory
The attacker uses RACE protocol commands to read pages of the earbuds’ flash memory. Inside that memory is a connection table — storing the Bluetooth addresses and names of previously paired devices, and most critically: the cryptographic Bluetooth Link Keys used to authenticate each paired connection.
Exploits: CVE-2025-20702 RACE protocol - Impersonate the Trusted Headphones
Armed with the stolen Link Key and Bluetooth address, the attacker’s device spoofs the earbuds — making their phone appear to the victim’s phone as a trusted, already-paired audio device. The victim’s phone accepts the connection as if it’s their own earbuds reconnecting.
The attacker no longer needs the earbuds at this point - Take Control of the Phone
Now connected as the “trusted headphones,” the attacker can: intercept and redirect phone calls, trigger voice assistants (Siri, Google) to issue commands, extract contacts and call history, read currently playing media, and issue AT commands over HFP to control the phone.
Full phone takeover via trusted Bluetooth relationship

This Is Bigger Than Beats: Affected Brands
The Beats Studio Buds patch is welcome — but it’s the tip of the iceberg. Because the vulnerability lives in Airoha’s shared chip and SDK, tens of millions of devices across the consumer audio industry are affected. ERNW confirmed vulnerabilities across nearly 30 product models from major global brands.
Products from Sony, JBL, Bose, Marshall, Jabra, Beyerdynamic, Teufel, Xiaomi, and more share the same vulnerable Airoha chip — the same chip Apple used in the Beats Studio Buds.
| Brand | Affected Products | Patch Status | Notes |
| Apple (Beats) | Beats Studio Buds | ✓ Patched Jun 2026 | Firmware 1B211 — auto-delivered near paired device |
| JBL | Live Buds 3, Endurance Race 2 | ✓ Patched Jul 2025 | Fastest major vendor to respond; via JBL Headphones app |
| Bose | QuietComfort Earbuds | ✓ Patched Sep 2025 | Fix via Bose QCE app v1.2.1; partial vulnerability only |
| Marshall | Multiple models | ⚠ Partial | Initially failed to respond to ERNW; acknowledged after public disclosure |
| Jabra | Elite 8 Active, Link 390 | ⚠ Mixed | Elite 8 Active not vulnerable to Classic vector; Link 390 patched Dec 2025 |
| Beyerdynamic | Multiple models | ✓ Patched | Proactively addressed following Airoha SDK update |
| Sony | WH-1000XM4/5/6, WF-1000XM3/4/5, WH-CH520, WH-XB910N, and more | ⚠ Unconfirmed | Initially failed to respond to ERNW; only acknowledged after public conference disclosure |
| Teufel, Xiaomi, JLab, others | Various models | ✗ Unknown | Many vendors unaware they use Airoha chips; no advisories published |
A critical industry-wide problem: Many manufacturers don’t even know their own products contain Airoha chips — because the Bluetooth hardware and firmware is often outsourced during development. When a supplier publishes a patch, vendors who don’t know they’re affected never apply it.
The Disclosure Timeline: 12 Months from Discovery to Apple’s Patch
MARCH 25, 2025
ERNW Discloses to Airoha
Dennis Heinze and Frieder Steinmetz contact Airoha Technology with full vulnerability details. No response for over two months.
May 27, 2025
Airoha Finally Responds — 63 Days Later
After repeated contact attempts, Airoha acknowledges the vulnerabilities. Communication improves from this point forward.
June 4, 2025
Airoha Releases Fixed SDK to Vendors
Airoha distributes a corrected Software Development Kit to all hardware partners — eight days before ERNW’s public disclosure. The patch is available; now vendors must apply it.
June 12, 2025
Partial Disclosure at TROOPERS 2025 (Germany)
ERNW presents findings publicly at the security conference. Details are deliberately limited to protect users of still-unpatched devices. Sony acknowledges the issue only after hearing it will be presented publicly.
July–September 2025
JBL and Bose Release Patches
JBL patches Live Buds 3 (July 8) and Endurance Race 2 (July 30) via the JBL Headphones app. Bose releases QuietComfort Earbuds fix via app update in September 2025.
December 27, 2025
Full Technical Disclosure + RACE Toolkit Released
ERNW publishes the full white paper, detailed attack methodology, and the RACE Toolkit — enabling users and security researchers to test whether their own devices are still vulnerable. Presented at 39C3 security conference.
June 16, 2026
Apple Finally Releases Beats Firmware 1B211
One full year after Airoha delivered the patched SDK. Apple describes the flaw as rooted in “open source code” and notes Apple software was among the affected projects. The patch auto-installs when earbuds are near a paired device.
Why This Matters for Businesses — The Hidden Attack Surface
This vulnerability sounds like a consumer electronics story. It isn’t. It’s a business security story — because your employees bring these devices to work every day.
Bluetooth audio devices are now part of the enterprise attack surface — yet they sit entirely outside traditional patch management programs and endpoint security tools.
Consider these real-world scenarios:
Executive calls in transit: A CEO wearing unpatched Beats on a flight or in an airport lounge takes a confidential board call — an attacker nearby could be listening to every word
Conference room exposure: Bluetooth headphones left in a meeting room during a sensitive legal, HR, or M&A discussion, with devices in pairing mode
Remote work: Employees using personal earbuds for client calls at home, in co-working spaces, or in cafés — devices IT has zero visibility into and zero control over
High-value targets: ERNW specifically named politicians, diplomats, CEOs, and journalists as priority targets for this type of proximity attack

Resolution: What Has Been Done
✅ What’s Fixed
- Airoha released a corrected SDK on June 4, 2025 — the root cause has been addressed at the chip level
- Apple Beats Studio Buds — fully patched via Firmware 1B211 (June 16, 2026). Auto-installs when earbuds are near a paired iPhone, iPad, or Mac
- JBL Live Buds 3 and Endurance Race 2 — patched via JBL Headphones app (July 2025)
- Bose QuietComfort Earbuds — patched via Bose QCE app v1.2.1 (September 2025)
- Jabra Link 390 — firmware fix released December 2025
- Marshall and Beyerdynamic — updates issued in months following Airoha’s SDK release
⚠️ What’s Still at Risk
- Sony’s full product lineup — no confirmed patches for WH-1000XM4/5/6, WF-1000XM3/4/5, and other affected models as of publication
- Dozens of smaller brands using Airoha chips without published advisories — Teufel, Xiaomi, JLab, and others
- Products that may never receive patches — older or discontinued models where vendors have no update mechanism
- Users who don’t know they need to update — Bluetooth firmware updates are rarely surfaced prominently, and most users don’t check

What You and Your Organization Should Do
- Update Beats Studio Buds to Firmware 1B211 Right Now
Place your Beats Studio Buds in their charging case and bring them within Bluetooth range of your paired iPhone, iPad, or Mac. The firmware update installs automatically. To verify: go to Settings → Bluetooth → tap the ⓘ icon next to your Beats Studio Buds → check the firmware version shows 1B211 or later. - Check All Bluetooth Audio Devices for Manufacturer Updates
If your organization or employees use Sony, Bose, JBL, Marshall, Jabra, or Beyerdynamic headphones or earbuds, open each brand’s companion app and check for firmware updates. For Sony specifically: check the Sony Headphones Connect app for each device model. For Bose: update the Bose QCE app. Don’t assume a device without an update prompt is safe — some vendors haven’t published advisories at all. - Use the RACE Toolkit to Test Device Vulnerability Status
ERNW published the RACE Toolkit on December 27, 2025 — specifically to allow users and security professionals to verify whether their specific device model is still vulnerable. Security teams can use this to test any device before clearing it for use in sensitive contexts. The toolkit is available via ERNW’s technical white paper at insinuator.net. - Don’t Leave Bluetooth Devices in Pairing Mode
The attack window only exists when the device is actively broadcasting pair requests — in pairing mode. Educate employees: don’t leave earbuds in the charging case with the case open and lid up (which triggers pairing mode on many models) in public spaces. If the device is paired and connected to your phone, the Classic Bluetooth attack vector requires the attacker to first disconnect that paired session — which is harder to do silently. - Use Wired Audio for Sensitive Meetings and Calls
For executive calls, legal consultations, HR discussions, M&A negotiations, or any conversation that would be damaging if overheard — use wired headphones or the phone’s built-in speaker in a secure room. Removing Bluetooth entirely removes the attack surface for the duration of those conversations. This is a simple, zero-cost interim control that can be implemented immediately. - Delete Old Unused Bluetooth Pairings
The attack chain that allows phone takeover requires stealing Bluetooth Link Keys stored in the earbuds’ flash memory. Removing old paired devices from both your phone and your earbuds reduces the value of that data if it were extracted. Go through all Bluetooth paired device lists and remove anything you no longer actively use. - Include Bluetooth Firmware in Your Patch Management Program
Laptops, phones, and servers get patched on a regular cycle. Bluetooth headphones, earbuds, smart speakers, and other peripheral devices almost never do — because they sit outside every standard patch management tool. This incident is a clear signal that peripheral device firmware needs to be included in your IT asset inventory and update cadence, especially for BYOD environments.

Security doesn’t stop at the laptop. Every device near your employees’ conversations is a risk.
AvantGuard helps organizations identify the full attack surface — including peripheral devices, IoT endpoints, and BYOD devices that traditional security tools miss. Let’s audit your environment and build a complete device security policy that leaves no gaps.



