Apple released a firmware update for Beats Studio Buds to fix a flaw that could let someone nearby listen through the earbuds' microphone before they are paired. The issue, CVE-2025-20701, affects Airoha Bluetooth system-on-chip code used in the earbuds and was fixed in Beats Firmware Update 1B211. Apple says an attacker within Bluetooth range could exploit the unpaired device while it is seeking pair requests; researchers previously showed related Airoha flaws CVE-2025-20700 and CVE-2025-20702 could also help attackers hijack headphone functions and issue call commands.
Why it matters: People using affected Beats earbuds could be exposed to nearby spying even without pairing the device first. Users should ensure their Beats Studio Buds receive firmware 1B211 by pairing them with an iPhone, iPad, or Mac and confirming the update in Bluetooth settings.
SecurityWeek News
2026.06.19
80% relevant
This roundup reiterates Apple's patch for the Beats Studio Buds Bluetooth eavesdropping flaw and serves as a secondary report on the same firmware security update.
info@thehackernews.com (The Hacker News)
2026.06.19
99% relevant
This article reports the same underlying event: Apple's patch for CVE-2025-20701 in Beats Studio Buds that could allow a nearby attacker to access the microphone before pairing is complete.
Sergiu Gatlan
2026.06.18
100% relevant
This article establishes a distinct security-update story: Apple has now issued a fix for a specific disclosed Bluetooth eavesdropping vulnerability affecting Beats Studio Buds.
← Back to all stories