Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a nearby attacker listen through the microphone of an unpaired device. Apple shipped Beats Firmware Update 1B211 to patch the bug. Researchers also built a proof-of-concept exploit and said chaining it with CVE-2025-20700 and CVE-2025-20702 can expand control to calls and device memory.
Related Happenings
Apple A12/S4/S5/A13 BootROM usbliter8 authentication bypass flaw
Vulnerability
H score27
First: 22.06.2026 17:00
Last: 22.06.2026 17:00
Sources 1
About this happening:
Researchers disclosed usbliter8, an unpatchable BootROM flaw affecting Apple A12, S4/S5, and A13 SoCs, creating boot-chain compromise risk for devices with physical...
Apple A12/S4/S5/A13 BootROM usbliter8 authentication bypass flaw
VulnerabilityAbout this happening: Researchers disclosed usbliter8, an unpatchable BootROM flaw affecting Apple A12, S4/S5, and A13 SoCs, creating boot-chain compromise risk for devices with physical...
Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
Vulnerability
H score0
First: 19.06.2026 21:37
Last: 19.06.2026 21:37
Sources 1
About this happening:
A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...
Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
VulnerabilityAbout this happening: A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical Analysis
H score33
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical AnalysisAbout this happening: Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Timeline
-
18.06.2026 15:23 3 articles · 27d ago
Apple patches Beats Studio Buds Bluetooth flaw with Beats Firmware Update 1B211
Mitigation Patch UpdateApple released security updates for Beats Studio Buds to fix CVE-2025-20701 in Airoha system-on-a-chip (SoCs), a Bluetooth-range flaw that could let an attacker listen through the microphone of a device that is not yet paired and actively seeking pair requests. Beats Firmware Update 1B211 is automatically delivered to vulnerable headphones when they are paired and within Bluetooth range of the user's iPhone, iPad, or Mac.
Show sources
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversations — www.bleepingcomputer.com — 18.06.2026 15:23
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversations — www.bleepingcomputer.com — 18.06.2026 15:23
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone — thehackernews.com — 19.06.2026 09:36