Apple Beats Firmware Patch Fixes Unauthenticated Mic Access

Apple patches a critical Bluetooth vulnerability in Beats Studio Buds that allowed hackers to access the microphone without authentication.

By Central
The firmware version 1B211 addresses CVE-2025-20701, a Bluetooth flaw in unpaired Beats Studio Buds.
Highlights
  • The vulnerability allows unauthenticated attackers to activate the microphone on unpaired Beats Studio Buds seeking a connection.
  • Apple automatically delivers the firmware update when Beats Studio Buds are paired with a trusted Apple device.
  • CVE-2025-20701 is part of a broader set of Bluetooth security flaws disclosed in 2024 affecting multiple vendors.

Apple has released a critical firmware update for Beats Studio Buds that closes a vulnerability allowing nearby unauthenticated attackers to activate the microphone on unpaired devices actively seeking a Bluetooth connection. The patch, firmware version 1B211, addresses CVE-2025-20701, one of several Bluetooth security flaws disclosed last year that affect devices from multiple major hardware vendors. The update applies automatically when Beats Studio Buds are paired with an Apple device, making it seamless for users to protect themselves. This development arrives amid a particularly active week in cybersecurity, spanning supply chain compromises, state-sponsored espionage campaigns, and large-scale data breaches.

Apple Beats Studio Buds Firmware Update Closes Microphone Access Vulnerability

What is CVE-2025-20701? It is a Bluetooth vulnerability affecting Beats Studio Buds that allows an unauthenticated attacker within radio range to access the device microphone when the earbuds are in an unpaired, connection-seeking state. The issue resides in the Bluetooth handshake and device discovery process, where unauthenticated requests can trigger microphone activation without user consent or notification. Apple describes the vulnerability as affecting unpaired devices actively seeking a connection, meaning the attack surface is limited to moments when the earbuds are in their discovery state. The update is delivered automatically when the Beats Studio Buds are paired with an iPhone, iPad, or Mac running current software. CVE-2025-20701 is among three Bluetooth security issues disclosed in 2024 by researchers, which were found to impact silicon and firmware from multiple vendors including Airoha, whose chipsets are used in a wide range of consumer audio devices.

Broader Security Landscape: A Week of Critical Developments

Supply Chain Attacks Hit WordPress and IDE Ecosystems

More than 1.2 million WordPress sites were compromised in a supply chain attack targeting Awesome Motive’s OptinMonster, TrustPulse, and PushEngage plugins. Attackers injected malicious JavaScript into CDN scripts that activated for logged-in administrators, creating rogue admin accounts and installing a hidden backdoor plugin. The breach originated from a compromised UpdraftPlus instance and a stolen CDN key. Separately, at least 15 malicious AI coding assistant plugins were discovered in the JetBrains Marketplace, collectively amassing nearly 70,000 installs. These plugins exfiltrated OpenAI, DeepSeek, and other API keys in plaintext to an attacker-controlled server while appearing to function as legitimate tools.

State-Sponsored Threats and Persistent Infiltration

The China-nexus actor known as Velvet Ant maintained stealth access to an air-gapped critical infrastructure network for nearly a decade, starting around 2016. The group chained internet-facing footholds with Nginx proxies and backdoored PAM and OpenSSH components for credential theft, deploying multiple variants of custom tools across the compromised environment. Remediation efforts were described as complex due to the depth of the access achieved.

Critical Flaws in Widely Used Software

An authentication bypass in phpBB versions up to 3.3.16 and 4.0.0-a2 allows a single unauthenticated HTTP request to impersonate any user, including administrators. Users are urged to upgrade to version 3.3.17 or the latest master branch. Meanwhile, critical vulnerabilities in the SiderAI and MaxAI Chrome extensions, with over 10 million combined installs, can allow malicious websites to trigger arbitrary extension actions including screenshot capture and AI memory access. No vendor response has been reported, and users are advised to remove the extensions until patches are issued.

Fraud, Data Leaks, and Regulatory Actions

The FTC reported that imposter scams cost Americans $3.5 billion in 2025, nearly triple the losses recorded in 2020, with bank and government impersonation schemes driving the bulk of the damage. Overall fraud losses reached a record $16 billion. The ShinyHunters hacking group published data from Madison Square Garden, including risk assessments and contact information for Knicks talent and customer correspondence, following a breach on June 5. The group continues its pattern of public data leaks to pressure victims into compliance.

What Users and Organizations Should Do Now

Beats Studio Buds users should ensure their devices are paired with a trusted Apple device running current software to receive the firmware update automatically. For the broader set of threats highlighted this week, users should take immediate action: update phpBB instances to version 3.3.17 or later; remove the SiderAI and MaxAI Chrome extensions until vendor patches are released; audit WordPress sites for signs of compromise, particularly admin accounts or unfamiliar plugins; and review JetBrains Marketplace plugin inventory for any AI coding assistant plugins from unknown vendors. Organizations using Google Cloud Config Connector should assess their IAM policy configurations, as a confused deputy vulnerability remains unpatched and can allow Kubernetes namespace users to escalate to Organization Owner. Enabling multi-factor authentication across all accounts and using a reputable password manager with end-to-end encryption remain essential baseline protections against the evolving threat landscape.

Share This Article