<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f" -->

---
title: Apple fixes Beats Studio Buds flaw that let hackers spy...
description: Apple has patched a high-severity Bluetooth vulnerability (CVE-2025-20701) in Beats Studio Buds firmware that allowed attackers within Bluetooth range to...
canonical: https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Apple fixes Beats Studio Buds flaw that let hackers spy on conversations | daily.dev
og:description: Apple has patched a high-severity Bluetooth vulnerability (CVE-2025-20701) in Beats Studio Buds firmware that allowed attackers within Bluetooth range to...
og:url: https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f
og:image: https://api.daily.dev/og/posts/DCWnvVQ5F.png
og:image:alt: Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Apple fixes Beats Studio Buds flaw that let hackers spy on conversations

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Apple has patched a high-severity Bluetooth vulnerability (CVE-2025-20701) in Beats Studio Buds firmware that allowed attackers within Bluetooth range to eavesdrop on conversations through the device's microphone without any authentication or pairing. The flaw originates in Airoha system-on-a-chip open source code and was discovered by ERNW GmbH researchers, who demonstrated a proof-of-concept exploit at the TROOPERS security conference. When chained with two related CVEs, attackers could fully take over the headphones, read/write device RAM and flash, retrieve call history and contacts, and even initiate calls. The fix is delivered automatically via Beats Firmware Update 1B211 when the earbuds are in range of a paired Apple device.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations>

## Questions this post answers

### What is CVE-2025-20701 and how does it affect Beats Studio Buds?

CVE-2025-20701 is a Bluetooth vulnerability in the Airoha system-on-a-chip used in Beats Studio Buds that lets an attacker within Bluetooth range listen through the microphone of a device that isn't yet paired but is actively seeking pair requests. It stems from a missing authentication weakness in the Bluetooth BR/EDR radio, discovered by ERNW GmbH researchers Dennis Heinze and Frieder Steinmetz.

_Track Bluetooth security fixes like this one on daily.dev before rolling out firmware updates._

### How do I fix the Bluetooth eavesdropping vulnerability in my Beats Studio Buds?

Apple patched the flaw in Beats Firmware Update 1B211, which installs automatically once the earbuds are paired and within Bluetooth range of an iPhone, iPad, or Mac. Users can verify the update applied by opening Bluetooth settings on their device and tapping the info button next to the headphones.

_Developers supporting Bluetooth accessories follow firmware patch rollouts like this on daily.dev._

### Can chaining Bluetooth vulnerabilities let attackers fully take over Beats headphones?

Yes, chaining CVE-2025-20701 with CVE-2025-20700 and CVE-2025-20702 lets attackers use the Bluetooth Hands-Free Profile to hijack the connection between a phone and paired audio device, fully taking over the headphones without authentication or pairing. Attackers can read and write device RAM and flash, retrieve call history and contacts, and place calls after extracting Bluetooth link keys.

_Engineers assessing Bluetooth attack surfaces track vulnerability chains like this via daily.dev._

## Similar posts on daily.dev

- [Apple patches eavesdropping vulnerability in Beats Studio Buds](https://daily.dev/posts/apple-patches-eavesdropping-vulnerability-in-beats-studio-buds-emxppahlc) · Ars Technica · 0 upvotes · 0 comments
- [Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking](https://daily.dev/posts/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking-gemjsukrb) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#apple](https://daily.dev/tags/apple), [#bluetooth](https://daily.dev/tags/bluetooth)

[View this post on daily.dev](https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Apple fixes Beats Studio Buds flaw that let hackers spy on conversations","url":"https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f"},"datePublished":"2026-06-18T12:28:42.979Z","dateModified":"2026-09-14T07:58:54.375Z","description":"Apple has patched a high-severity Bluetooth vulnerability (CVE-2025-20701) in Beats Studio Buds firmware that allowed attackers within Bluetooth range to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/954ee407262629b98142e4ec0451daf4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/954ee407262629b98142e4ec0451daf4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,apple,bluetooth","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Apple fixes Beats Studio Buds flaw that let hackers spy on conversations"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations-dcwnvvq5f#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2025-20701 and how does it affect Beats Studio Buds?","acceptedAnswer":{"@type":"Answer","text":"CVE-2025-20701 is a Bluetooth vulnerability in the Airoha system-on-a-chip used in Beats Studio Buds that lets an attacker within Bluetooth range listen through the microphone of a device that isn't yet paired but is actively seeking pair requests. It stems from a missing authentication weakness in the Bluetooth BR/EDR radio, discovered by ERNW GmbH researchers Dennis Heinze and Frieder Steinmetz. Track Bluetooth security fixes like this one on daily.dev before rolling out firmware updates."}},{"@type":"Question","name":"How do I fix the Bluetooth eavesdropping vulnerability in my Beats Studio Buds?","acceptedAnswer":{"@type":"Answer","text":"Apple patched the flaw in Beats Firmware Update 1B211, which installs automatically once the earbuds are paired and within Bluetooth range of an iPhone, iPad, or Mac. Users can verify the update applied by opening Bluetooth settings on their device and tapping the info button next to the headphones. Developers supporting Bluetooth accessories follow firmware patch rollouts like this on daily.dev."}},{"@type":"Question","name":"Can chaining Bluetooth vulnerabilities let attackers fully take over Beats headphones?","acceptedAnswer":{"@type":"Answer","text":"Yes, chaining CVE-2025-20701 with CVE-2025-20700 and CVE-2025-20702 lets attackers use the Bluetooth Hands-Free Profile to hijack the connection between a phone and paired audio device, fully taking over the headphones without authentication or pairing. Attackers can read and write device RAM and flash, retrieve call history and contacts, and place calls after extracting Bluetooth link keys. Engineers assessing Bluetooth attack surfaces track vulnerability chains like this via daily.dev."}}]}
```

