Apple patches Beats Studio Buds eavesdropping flaw
🔒 Apple released a security update to fix a high-severity vulnerability in Beats Studio Buds that could let attackers within Bluetooth range listen through an unpaired device's microphone. The flaw (CVE-2025-20701) was found in Airoha SoC open-source code and disclosed by ERNW researchers at TROOPERS. Apple deployed Beats Firmware Update 1B211, which installs automatically when paired and in range; users can verify the firmware via Bluetooth settings. Chained with related CVEs, attackers could hijack HFP connections to issue phone commands or access contacts, though practical attacks are complex and require proximity.
