Back to Blog
CVE-2025-20701: Apple Beats Studio Buds — Bluetooth Mic Eavesdropping Risk (June 2026)
vulnerabilities

CVE-2025-20701: Apple Beats Studio Buds — Bluetooth Mic Eavesdropping Risk (June 2026)

breachwire TeamJun 20, 20262 min read

CVE-2025-20701 — Apple Beats Studio Buds

CVE-2025-20701 is a critical Bluetooth vulnerability in Apple Beats Studio Buds, allowing attackers within wireless range to eavesdrop on device microphones without pairing or user interaction. No authentication is required, and the flaw is present in the Airoha Bluetooth audio SDK. Apple has released a firmware update to address this issue. This vulnerability is not known to be actively exploited in the wild, but its ease of exploitation and impact on privacy elevate its risk profile.

Attack Vector

An attacker within Bluetooth range can exploit CVE-2025-20701 by sending crafted packets to vulnerable Beats Studio Buds. The exploit leverages a flaw in the Airoha Bluetooth audio SDK, bypassing pairing and authentication to remotely activate the microphone. No user interaction is required. The attacker can eavesdrop on conversations in real time, and the attack leaves no obvious trace for the user. No indicators of compromise (IOCs) have been published for this specific exploit.

Who Is at Risk

All users of Apple Beats Studio Buds running unpatched firmware are at risk. Organizations deploying Beats Studio Buds in sensitive environments, as well as users of Jabra and other devices using the Airoha Bluetooth audio SDK, should review their exposure. Apple, Beats, and Jabra have confirmed impact. Devices using Apple A12 and A13 chips are also affected by a separate BootROM hardware vulnerability (usbliter8 exploit), which enables persistent code execution via USB, but this is not patchable via software.

Patch & Mitigate

  • Patch: Update Beats Studio Buds to the latest firmware released by Apple as of June 2026. Check device settings or Apple support for update instructions.
  • Workaround: Disable Bluetooth when not in use. Avoid using Beats Studio Buds in sensitive locations until patched.
  • Detect: Monitor for unexpected Bluetooth connections or traffic to Beats Studio Buds. Review Bluetooth logs for anomalous pairing attempts, though this attack may not generate standard logs.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit Bluetooth proximity to gain unauthorized access to device microphones.
  • TA0005 — Defense Evasion: The exploit operates without user interaction and leaves minimal forensic evidence.
  • TA0009 — Collection: The attacker captures audio data directly from the device microphone.

Source: https://thehackernews.com/2026/06/apple-patches-beats-studio-buds-flaw.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: