All incidents

Apple patches Beats Studio Buds Bluetooth eavesdropping flaw (CVE-2025-20701)

vulnerabilityclosedJun 18, 2026 — Jun 19, 2026
Apple patches Beats Studio Buds Bluetooth eavesdropping flaw (CVE-2025-20701)

APPLE has released a firmware update for Beats Studio Buds to address a Bluetooth eavesdropping flaw tracked as CVE-2025-20701, which could allow nearby attackers to hijack the earbuds’ microphones. The update arrives as threat analysts note increased activity from the Velvet Ant espionage group, raising concerns about stealth intrusions via wireless peripherals. Apple’s support note describes the issue as an authentication gap during the pairing sequence. Users are urged to apply the patch promptly to prevent potential audio surveillance. Apple’s support note provides details.

The vulnerability stems from insufficient verification of the connecting device during the Bluetooth handshake, enabling an unauthenticated device to link and stream audio from the mic before pairing is finalised. This flaw has been assigned a CVSS score of 8.8, placing it in the high severity range. All Beats Studio Buds running firmware versions earlier than 1B211 are affected. The underlying issue resides in the Bluetooth stack supplied by Airoha Systems, a component also used by several other audio vendors. The NVD entry lists the technical specifics. The NVD entry provides the technical breakdown.

Exploitation requires the attacker to be within typical Bluetooth range, roughly ten metres, and to act while the earbuds are in discoverable or pairing mode. If successful, the malicious device can capture ambient conversations and transmit them to a remote listener. Apple’s firmware 1B211 introduces a stricter certificate check that blocks unknown devices from completing the handshake. The flaw was initially disclosed in a security advisory concerning Airoha chips, which prompted Jabra, Bose and JBL to release comparable fixes. Ars Technica outlines the chip‑level discovery and cross‑vendor impact. Ars Technica details the chip‑level origin.

Velvet Ant, known for targeting air‑gapped environments with sophisticated wireless techniques, has been observed experimenting with similar Bluetooth weaknesses in recent campaigns. To date, no public exploitation of CVE-2025-20701 has been attributed to the group, but the temporal overlap warrants attention. The patch dovetails with a series of advisories from manufacturers addressing authentication shortcomings in their wireless headsets. SecurityWeek highlights the broader trend of Bluetooth‑focused patches across the industry. SecurityWeek notes the broader trend.

Users should first confirm the firmware revision of their Beats Studio Buds by opening the Bluetooth settings screen on an iPhone, iPad or Mac and selecting the device info option. If the displayed version is older than 1B211, they should place the earbuds in their charging case, bring the case near a trusted Apple device and allow the update to download and install automatically. Keeping the earbuds connected to a power source during the process helps avoid interruptions. Disabling Bluetooth when the earbuds are not in use and avoiding pairing in crowded venues such as cafés or conference centres further limits exposure. Malwarebytes offers a concise walkthrough of these steps. Malwarebytes offers a step‑by‑step guide.

Security teams should maintain an inventory of all Bluetooth endpoints, correlating connection timestamps with asset logs to spot anomalous pairings. Enforcing a policy that permits only pre‑approved devices to complete pairing reduces the attack surface for rogue peripherals. Additionally, ensuring that macOS, iOS and iPadOS are current guarantees that Apple’s firmware delivery mechanism functions correctly, pushing updates without user intervention. Regular awareness reminders about the risks of pairing in uncontrolled spaces complement technical controls. The Hacker News summarises these defensive measures. The Hacker News summarises recommended defensive actions.

Intelligence briefing updated Jun 19, 2026

CVE-2025-20701 8.8 Velvet Ant
Root sourcesupport.apple.com
Timeline Coverage

Swipe to explore timeline