Apple fixes Beats Studio Buds Bluetooth eavesdropping flaw

Apple releases critical firmware update to stop nearby attackers from hijacking Beats Studio Buds microphones before pairing.

By Central
Beats Studio Buds get firmware 1B211 to patch an eavesdropping flaw in Airoha Bluetooth chipsets.
Highlights
  • The vulnerability allowed attackers within 10 meters to access the microphone before device pairing.
  • Apple's update addresses CVE-2025-20701, one of three Airoha chipset flaws disclosed by ERNW.
  • Beats Studio Buds users can verify the update by checking firmware version 1B211 in Bluetooth settings.

Apple has released Beats Firmware Update 1B211 to address a critical Bluetooth vulnerability, tracked as CVE-2025-20701, that could allow a nearby attacker to eavesdrop on conversations through the microphone of Beats Studio Buds before the device has been paired. The flaw, part of a broader set of vulnerabilities disclosed last year in widely used Airoha Bluetooth chipsets, posed a significant privacy risk to users, particularly those handling sensitive information. The update is now available for Beats Studio Buds and is delivered automatically when the headphones are connected to an iPhone, iPad, or Mac.

Understanding the Beats Studio Buds Bluetooth Eavesdropping Vulnerability

The security flaw, CVE-2025-20701, was discovered by cybersecurity researchers Dennis Heinze and Frieder Steinmetz of the German firm ERNW. According to Apple’s advisory, the vulnerability affects open-source code used by multiple projects and could be exploited by an attacker within Bluetooth range to access the microphone of a Beats Studio Buds device that is actively searching for a pairing connection but has not yet been paired. Apple did not disclose the specific technical details of the fix but confirmed the update resolves the issue.

The Broader Context: Airoha Chipset Flaws

This vulnerability is one of three critical Bluetooth flaws that ERNW disclosed in 2025 after analyzing firmware used in Airoha Bluetooth system-on-Chips (SoCs). Airoha, a subsidiary of MediaTek, is a major supplier of Bluetooth silicon for the true wireless stereo (TWS) market, providing chipsets and software development kits used by numerous consumer audio brands. During their research, Heinze and Steinmetz discovered that a diagnostic protocol known as RACE (Realtek/Airoha Command Extensions) was exposed over Bluetooth without proper authentication in many products.

The three flaws, tracked as CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702, enabled attackers within range to access sensitive functions, extract pairing information, read device memory, and, in some cases, access microphone audio streams. CVE-2025-20701, the specific flaw addressed by Apple, involved a lack of pairing enforcement over Bluetooth Classic connections. ERNW demonstrated that the issue could be abused to access audio-related services, allowing attackers to connect to vulnerable devices without authentication and potentially capture microphone input.

How the Attack Works and Who Is at Risk

While ERNW’s demonstrations required specialized knowledge, custom tooling, and close physical proximity—typically within approximately 10 meters—the researchers warned that the flaws posed a meaningful risk to high-profile targets. Journalists, executives, government officials, and others who regularly discuss sensitive information were identified as particularly vulnerable. The researchers also published a testing toolkit and technical documentation in December 2025, showing how affected devices could be abused to impersonate trusted Bluetooth accessories, trigger voice assistants, access call-related information, and conduct eavesdropping attacks.

Apple’s advisory does not indicate whether any real-world exploitation of CVE-2025-20701 has been observed. However, the availability of a public testing toolkit and the widespread use of Airoha chipsets in headphones and earbuds from numerous vendors underscore the importance of applying the firmware update promptly.

What Is the Beats Studio Buds Bluetooth Vulnerability?

The Beats Studio Buds Bluetooth vulnerability, CVE-2025-20701, is a security flaw that allows a nearby attacker to listen through the microphone of the earbuds before they have been paired with a device. The vulnerability exists in the open-source code used by multiple projects and is addressed by Apple’s Beats Firmware Update 1B211. Users should ensure their Beats Studio Buds are updated to the latest firmware to mitigate this risk.

How to Update Your Beats Studio Buds

Firmware updates for Beats devices are delivered automatically when the headphones are paired with an iPhone, iPad, or Mac and are within Bluetooth range. Users can verify their firmware version through the Bluetooth settings on their Apple device. To check, navigate to Settings > Bluetooth, tap the “i” icon next to your Beats Studio Buds, and look for the firmware version. If it is not 1B211, ensure your device is connected to the internet and within range of your Apple device to trigger the automatic update.

What Affected Users Should Do Now

For users of Beats Studio Buds, the immediate action is to confirm that the firmware has been updated to version 1B211. This is the only confirmed fix for CVE-2025-20701 on these devices. Beyond this specific update, users should adopt general Bluetooth security best practices. When not in use, disable Bluetooth on your devices to reduce the attack surface. Avoid leaving Bluetooth headphones in pairing mode in public or untrusted environments. For those who regularly discuss sensitive information, consider using a reputable wired headset or a Bluetooth device from a vendor with a strong track record of security updates. More broadly, this incident highlights the importance of choosing audio devices from manufacturers that provide regular firmware updates and transparent security advisories. When selecting any wireless audio product, look for a vendor that demonstrates a commitment to patching vulnerabilities and provides clear documentation on how to apply updates. This proactive approach is the most effective defense against the evolving landscape of Bluetooth-based attacks.

Share This Article