Find notable cyber news and cases, enriched with sources, timelines, and signals.

Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 24
2 unique sources, 2 articles

Summary

Hide ▲

Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a nearby attacker listen through the microphone of an unpaired device. Apple shipped Beats Firmware Update 1B211 to patch the bug. Researchers also built a proof-of-concept exploit and said chaining it with CVE-2025-20700 and CVE-2025-20702 can expand control to calls and device memory.

Related Happenings

Apple A12/S4/S5/A13 BootROM usbliter8 authentication bypass flaw

Vulnerability
H score27 First: 22.06.2026 17:00 Last: 22.06.2026 17:00 Sources 1

About this happening: Researchers disclosed usbliter8, an unpatchable BootROM flaw affecting Apple A12, S4/S5, and A13 SoCs, creating boot-chain compromise risk for devices with physical...

Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw

Vulnerability
H score0 First: 19.06.2026 21:37 Last: 19.06.2026 21:37 Sources 1

About this happening: A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...

Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage

Technical Analysis
H score33 First: 26.03.2026 15:10 Last: 26.03.2026 15:10 Sources 1

About this happening: Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...

Timeline

  1. 18.06.2026 15:23 3 articles · 27d ago

    Apple patches Beats Studio Buds Bluetooth flaw with Beats Firmware Update 1B211

    Mitigation Patch Update

    Apple released security updates for Beats Studio Buds to fix CVE-2025-20701 in Airoha system-on-a-chip (SoCs), a Bluetooth-range flaw that could let an attacker listen through the microphone of a device that is not yet paired and actively seeking pair requests. Beats Firmware Update 1B211 is automatically delivered to vulnerable headphones when they are paired and within Bluetooth range of the user's iPhone, iPad, or Mac.

    Show sources