Blog Details

A person in a hoodie uses a laptop next to the Beats logo and sound waves. The text reads: "Your earbuds could be eavesdropping on you — Apple patches critical Beats flaw." Digital security icons are in the background.

Your Earbuds Could Be Eavesdropping on YouApple Patches Critical Beats Flaw

A highlighted notification states an Apple firmware update for Beats Studio Buds fixes a critical Beats flaw, warning that other earbuds using the same chip may remain unpatched. The update is titled "Patch Available: Beats Firmware Update 1B211.

What Happened

On June 16, 2026, Apple quietly released Beats Firmware Update 1B211 — a security patch for its Beats Studio Buds wireless earbuds. The update addresses a high-severity vulnerability that could have allowed an attacker sitting nearby to listen through the earbuds’ microphone without ever pairing with the device.

The vulnerability, tracked as CVE-2025-20701, was originally discovered and disclosed by security researchers Dennis Heinze and Frieder Steinmetz of the German cybersecurity firm ERNW GmbH. They first presented their findings at the TROOPERS security conference in June 2025 — which means Apple’s patch arrived a full twelve months after the vulnerability was first publicly known.

In that twelve-month window, every pair of Beats Studio Buds in pairing mode — in offices, coffee shops, airports, and conference rooms around the world — was potentially exposed.

Text box with a purple background contains a quote: "Apple’s official advisory stated: 'An attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired...' highlighting a potential Beats flaw with certain earbuds.

The Root Cause: The Airoha RACE Protocol

To understand why this happened, you need to understand Airoha Technology — a subsidiary of MediaTek and one of the largest suppliers of Bluetooth System-on-Chips (SoCs) in the consumer audio market. Airoha chips power earbuds and headphones from dozens of the world’s most recognized audio brands.

What ERNW researchers discovered was that Airoha’s chips expose a powerful custom debug protocol called RACE (Remote Access Control Engine) over two separate Bluetooth interfaces — and crucially, neither of them required authentication

Security researchers at ERNW GmbH found that Airoha’s Bluetooth chips expose a powerful debug protocol without any authentication — silently accessible by anyone within Bluetooth range.

The RACE protocol was designed as a debugging and control interface during manufacturing and development. The problem: Airoha left it fully active and completely unauthenticated in consumer devices shipping to millions of customers. Any attacker within Bluetooth range could access it — no pairing, no credentials, no interaction from the device owner required.

The Three CVEs: What Each Flaw Does

A table listing three Bluetooth vulnerabilities by CVE, flaw type, interface, severity (High, CVSS 8.8, Critical), and impact—including issues like unauthorized access and eavesdropping affecting Apple devices and Beats flaw in earbuds.

Individually, each CVE is serious. When chained together, they enable a complete device takeover — and an attack chain that goes far beyond just listening through a microphone.

How the Attack Works: Step by Step


ERNW researchers built and demonstrated a working proof-of-concept. Here is exactly what an attacker in Bluetooth range can do:

  1. Connect Silently
    The attacker’s device discovers earbuds in pairing mode and connects via BLE or Bluetooth Classic — completely silently, with no notification to the device owner. No pairing prompt appears. The owner has no idea anyone has connected.
    Exploits: CVE-2025-20700 (BLE) or CVE-2025-20701 (Classic)

  2. Access the Microphone
    Using the Hands-Free Profile (HFP) available over the unauthenticated Classic Bluetooth connection, the attacker initiates a two-way audio connection and begins receiving live audio from the earbuds’ microphone — capturing ambient conversations, calls, and sensitive discussions.
    Exploits: CVE-2025-20701 + HFP Bluetooth profile

  3. Dump Flash Memory
    The attacker uses RACE protocol commands to read pages of the earbuds’ flash memory. Inside that memory is a connection table — storing the Bluetooth addresses and names of previously paired devices, and most critically: the cryptographic Bluetooth Link Keys used to authenticate each paired connection.
    Exploits: CVE-2025-20702 RACE protocol

  4. Impersonate the Trusted Headphones
    Armed with the stolen Link Key and Bluetooth address, the attacker’s device spoofs the earbuds — making their phone appear to the victim’s phone as a trusted, already-paired audio device. The victim’s phone accepts the connection as if it’s their own earbuds reconnecting.
    The attacker no longer needs the earbuds at this point

  5. Take Control of the Phone
    Now connected as the “trusted headphones,” the attacker can: intercept and redirect phone calls, trigger voice assistants (Siri, Google) to issue commands, extract contacts and call history, read currently playing media, and issue AT commands over HFP to control the phone.
    Full phone takeover via trusted Bluetooth relationship
A highlighted box with bold text stating, "No phishing. No malware. No user interaction." followed by a quote explaining that any vulnerable device—including Apple or Beats earbuds—can be compromised if an attacker is within Bluetooth range.

This Is Bigger Than Beats: Affected Brands

The Beats Studio Buds patch is welcome — but it’s the tip of the iceberg. Because the vulnerability lives in Airoha’s shared chip and SDK, tens of millions of devices across the consumer audio industry are affected. ERNW confirmed vulnerabilities across nearly 30 product models from major global brands.

Products from Sony, JBL, Bose, Marshall, Jabra, Beyerdynamic, Teufel, Xiaomi, and more share the same vulnerable Airoha chip — the same chip Apple used in the Beats Studio Buds.

BrandAffected ProductsPatch StatusNotes
Apple (Beats)Beats Studio Buds✓ Patched Jun 2026Firmware 1B211 — auto-delivered near paired device
JBLLive Buds 3, Endurance Race 2✓ Patched Jul 2025Fastest major vendor to respond; via JBL Headphones app
BoseQuietComfort Earbuds✓ Patched Sep 2025Fix via Bose QCE app v1.2.1; partial vulnerability only
MarshallMultiple models⚠ PartialInitially failed to respond to ERNW; acknowledged after public disclosure
JabraElite 8 Active, Link 390⚠ MixedElite 8 Active not vulnerable to Classic vector; Link 390 patched Dec 2025
BeyerdynamicMultiple models✓ PatchedProactively addressed following Airoha SDK update
SonyWH-1000XM4/5/6, WF-1000XM3/4/5, WH-CH520, WH-XB910N, and more⚠ UnconfirmedInitially failed to respond to ERNW; only acknowledged after public conference disclosure
Teufel, Xiaomi, JLab, othersVarious models✗ UnknownMany vendors unaware they use Airoha chips; no advisories published

A critical industry-wide problem: Many manufacturers don’t even know their own products contain Airoha chips — because the Bluetooth hardware and firmware is often outsourced during development. When a supplier publishes a patch, vendors who don’t know they’re affected never apply it.

The Disclosure Timeline: 12 Months from Discovery to Apple’s Patch

MARCH 25, 2025
ERNW Discloses to Airoha

Dennis Heinze and Frieder Steinmetz contact Airoha Technology with full vulnerability details. No response for over two months.

May 27, 2025
Airoha Finally Responds — 63 Days Later

After repeated contact attempts, Airoha acknowledges the vulnerabilities. Communication improves from this point forward.

June 4, 2025
Airoha Releases Fixed SDK to Vendors

Airoha distributes a corrected Software Development Kit to all hardware partners — eight days before ERNW’s public disclosure. The patch is available; now vendors must apply it.

June 12, 2025
Partial Disclosure at TROOPERS 2025 (Germany)

ERNW presents findings publicly at the security conference. Details are deliberately limited to protect users of still-unpatched devices. Sony acknowledges the issue only after hearing it will be presented publicly.

July–September 2025
JBL and Bose Release Patches


JBL patches Live Buds 3 (July 8) and Endurance Race 2 (July 30) via the JBL Headphones app. Bose releases QuietComfort Earbuds fix via app update in September 2025.

December 27, 2025
Full Technical Disclosure + RACE Toolkit Released


ERNW publishes the full white paper, detailed attack methodology, and the RACE Toolkit — enabling users and security researchers to test whether their own devices are still vulnerable. Presented at 39C3 security conference.

June 16, 2026
Apple Finally Releases Beats Firmware 1B211

One full year after Airoha delivered the patched SDK. Apple describes the flaw as rooted in “open source code” and notes Apple software was among the affected projects. The patch auto-installs when earbuds are near a paired device.
Why This Matters for Businesses — The Hidden Attack Surface

This vulnerability sounds like a consumer electronics story. It isn’t. It’s a business security story — because your employees bring these devices to work every day.

Bluetooth audio devices are now part of the enterprise attack surface — yet they sit entirely outside traditional patch management programs and endpoint security tools.

Consider these real-world scenarios:

Executive calls in transit: A CEO wearing unpatched Beats on a flight or in an airport lounge takes a confidential board call — an attacker nearby could be listening to every word

Conference room exposure: Bluetooth headphones left in a meeting room during a sensitive legal, HR, or M&A discussion, with devices in pairing mode


Remote work: Employees using personal earbuds for client calls at home, in co-working spaces, or in cafés — devices IT has zero visibility into and zero control over


High-value targets: ERNW specifically named politicians, diplomats, CEOs, and journalists as priority targets for this type of proximity attack

A highlighted quote explains that devices like Apple earbuds are often excluded from security updates, making them targets for attackers, citing the Beats flaw CVE-2025-20701 as an example.

Resolution: What Has Been Done

✅ What’s Fixed

  • Airoha released a corrected SDK on June 4, 2025 — the root cause has been addressed at the chip level
  • Apple Beats Studio Buds — fully patched via Firmware 1B211 (June 16, 2026). Auto-installs when earbuds are near a paired iPhone, iPad, or Mac
  • JBL Live Buds 3 and Endurance Race 2 — patched via JBL Headphones app (July 2025)
  • Bose QuietComfort Earbuds — patched via Bose QCE app v1.2.1 (September 2025)
  • Jabra Link 390 — firmware fix released December 2025
  • Marshall and Beyerdynamic — updates issued in months following Airoha’s SDK release

⚠️ What’s Still at Risk

  • Sony’s full product lineup — no confirmed patches for WH-1000XM4/5/6, WF-1000XM3/4/5, and other affected models as of publication
  • Dozens of smaller brands using Airoha chips without published advisories — Teufel, Xiaomi, JLab, and others
  • Products that may never receive patches — older or discontinued models where vendors have no update mechanism
  • Users who don’t know they need to update — Bluetooth firmware updates are rarely surfaced prominently, and most users don’t check
A highlighted text box explains the systemic nature of the patching problem, noting that even after fixes—such as with a Beats flaw—vendors and users may not apply updates, leaving many Apple devices and earbuds vulnerable and unpatched.

What You and Your Organization Should Do

  • Update Beats Studio Buds to Firmware 1B211 Right Now

    Place your Beats Studio Buds in their charging case and bring them within Bluetooth range of your paired iPhone, iPad, or Mac. The firmware update installs automatically. To verify: go to Settings → Bluetooth → tap the ⓘ icon next to your Beats Studio Buds → check the firmware version shows 1B211 or later.

  • Check All Bluetooth Audio Devices for Manufacturer Updates

    If your organization or employees use Sony, Bose, JBL, Marshall, Jabra, or Beyerdynamic headphones or earbuds, open each brand’s companion app and check for firmware updates. For Sony specifically: check the Sony Headphones Connect app for each device model. For Bose: update the Bose QCE app. Don’t assume a device without an update prompt is safe — some vendors haven’t published advisories at all.

  • Use the RACE Toolkit to Test Device Vulnerability Status

    ERNW published the RACE Toolkit on December 27, 2025 — specifically to allow users and security professionals to verify whether their specific device model is still vulnerable. Security teams can use this to test any device before clearing it for use in sensitive contexts. The toolkit is available via ERNW’s technical white paper at insinuator.net.

  • Don’t Leave Bluetooth Devices in Pairing Mode

    The attack window only exists when the device is actively broadcasting pair requests — in pairing mode. Educate employees: don’t leave earbuds in the charging case with the case open and lid up (which triggers pairing mode on many models) in public spaces. If the device is paired and connected to your phone, the Classic Bluetooth attack vector requires the attacker to first disconnect that paired session — which is harder to do silently.

  • Use Wired Audio for Sensitive Meetings and Calls

    For executive calls, legal consultations, HR discussions, M&A negotiations, or any conversation that would be damaging if overheard — use wired headphones or the phone’s built-in speaker in a secure room. Removing Bluetooth entirely removes the attack surface for the duration of those conversations. This is a simple, zero-cost interim control that can be implemented immediately.

  • Delete Old Unused Bluetooth Pairings

    The attack chain that allows phone takeover requires stealing Bluetooth Link Keys stored in the earbuds’ flash memory. Removing old paired devices from both your phone and your earbuds reduces the value of that data if it were extracted. Go through all Bluetooth paired device lists and remove anything you no longer actively use.

  • Include Bluetooth Firmware in Your Patch Management Program

    Laptops, phones, and servers get patched on a regular cycle. Bluetooth headphones, earbuds, smart speakers, and other peripheral devices almost never do — because they sit outside every standard patch management tool. This incident is a clear signal that peripheral device firmware needs to be included in your IT asset inventory and update cadence, especially for BYOD environments.

A summary chart with six labeled boxes detailing a Bluetooth vulnerability (CVE-2025-20701), its discovery, affected devices like Apple earbuds, attack methods, resolution status, and recommended action for users.

Security doesn’t stop at the laptop. Every device near your employees’ conversations is a risk.

AvantGuard helps organizations identify the full attack surface — including peripheral devices, IoT endpoints, and BYOD devices that traditional security tools miss. Let’s audit your environment and build a complete device security policy that leaves no gaps.

Leave A Comment

At vero eos et accusamus et iusto odio digni goikussimos ducimus qui to bonfo blanditiis praese. Ntium voluum deleniti atque.

Melbourne, Australia
(Sat - Thursday)
(10am - 05 pm)