Apple patches eavesdropping vulnerability in Beats Studio Buds

Apple releases a critical firmware update to fix a zero-click Bluetooth flaw that could let attackers eavesdrop on conversations through Beats Studio Buds.

By Central
CVE-2025-20701 affects the Bluetooth stack of Beats Studio Buds and is rated high severity.
Highlights
  • The vulnerability, tracked as CVE-2025-20701, resides in the Bluetooth implementation of Beats Studio Buds.
  • Security researchers at Sentinel One detailed the flaw, which allows an unauthenticated attacker to intercept audio streams.
  • Users are urged to install the firmware update immediately through the companion app on iOS or Android.

Apple has released a security update to address an eavesdropping vulnerability affecting Beats Studio Buds, tracked as CVE-2025-20701. The flaw, which resides in the Bluetooth implementation of the wireless earbuds, could allow an attacker within wireless range to intercept audio streams and listen in on conversations without the user’s knowledge. The patch arrives as part of a broader cycle of firmware updates aimed at closing remote code execution and audio injection paths discovered in the Airoha chipset powering the devices.

Security researchers at Sentinel One have provided a technical breakdown of the vulnerability, detailing how an unauthenticated attacker could exploit the Bluetooth pairing mechanism to gain unauthorized access to the audio stream. The attack chain does not require the target to accept a connection request, making it a zero-click exploit in certain scenarios. While Apple has rated the vulnerability as high severity, the company has not disclosed evidence of active exploitation in the wild. Users of Beats Studio Buds are advised to install the latest firmware update immediately through the iOS or Android companion app.

What Is CVE-2025-20701 and How Does It Work?

CVE-2025-20701 is an audio eavesdropping vulnerability in the Bluetooth stack of Beats Studio Buds. The flaw stems from improper validation of Bluetooth connection parameters during the handshake process, allowing a nearby attacker to inject themselves into an existing audio session. Once connected illicitly, the attacker can capture live audio from the microphone or redirect the audio output to a device under their control. The exploit requires the attacker to remain within Bluetooth range, typically around 30 feet, throughout the duration of the attack. This physical proximity constraint is the primary factor that has likely limited real-world exploitation.

Researchers Heinze and Steinmetz, who previously disclosed a related set of vulnerabilities in the Airoha chipset, demonstrated last year that the full attack chain could extend beyond eavesdropping. Their work showed that attackers could retrieve call history, access contacts, and even initiate calls to arbitrary numbers from a paired device. The exact capabilities depend on the operating system and hardware features of the victim’s paired smartphone, as Bluetooth function sets vary significantly between Android and iOS platforms.

Context: A Broader Bluetooth Vulnerability Landscape

The Beats Studio Buds flaw is not an isolated incident. In January, researchers disclosed a family of vulnerabilities dubbed WhisperPair, which targets Bluetooth devices connected through Google Fast Pair. WhisperPair allows attackers to hijack active Bluetooth connections, eavesdrop on audio, and geolocate paired devices by exploiting weaknesses in the proprietary Fast Pair protocol. The affected ecosystem spans more than a dozen device models from ten manufacturers, including Sony, Nothing, JBL, OnePlus, and Google itself. The breadth of affected hardware underscores a systemic challenge in Bluetooth security: the protocol’s complexity and the prevalence of proprietary extensions create recurring opportunities for remote audio access.

Bluetooth eavesdropping vulnerabilities of this nature remain rare in active exploitation reports. The technical complexity of chaining together the necessary steps, combined with the requirement for sustained physical proximity, makes mass exploitation impractical. However, targeted attacks against individuals such as corporate executives, political figures, or journalists remain a plausible threat scenario. For users concerned about sophisticated surveillance risks, the operational security measure of disabling Bluetooth when not in use is the single most effective countermeasure.

What Affected Users Should Do Now

For owners of Beats Studio Buds, the immediate step is to update the device firmware to the latest version. The update is delivered through the Beats app on iOS or the Beats by Dre app on Android. Users should ensure their earbuds are connected, navigate to the firmware section, and follow the on-screen prompts to install the patch. After updating, confirm the firmware version matches the patched release indicated by Apple.

Beyond this specific vulnerability, users can adopt general Bluetooth hygiene practices to reduce exposure to similar attacks. Disable Bluetooth on smartphones, laptops, and tablets when wireless headphones or peripherals are not actively in use. Avoid leaving Bluetooth discoverable in public spaces, and unpair devices that are no longer used regularly. For those who frequently work in public environments or handle sensitive conversations, consider using a wired headset or a Bluetooth device that supports modern secure pairing standards such as Bluetooth 5.2 or later with LE Secure Connections. Selecting a reputable Bluetooth headset with a proven track record of timely firmware updates is a practical baseline defense against the next generation of wireless audio threats.

Share This Article