More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Apple just fixed a Bluetooth authentication flaw in Beats Studio Buds (CVE-2025-20701) that let an attacker in range pose as a pairing device and grab audio from your earbuds’ mic before you even finish pairing. The vulnerable chip is made by Airoha and sits in a bunch of wireless audio gear; researchers at a German security conference last year showed that by chaining this bug with other weaknesses in the same SoC, an attacker could also steal Bluetooth keys, fake trusted headphones and even hijack calls or trigger your voice assistant.
Exploiting it takes custom hardware, specialized software and close proximity, so random passers-by aren’t lining up to eavesdrop on you. But a determined stalker or a high-value target would be vulnerable until you update. The root cause is a missing identity check during the earbuds’ pairing handshake—if your Beats are searching for a source, any nearby device pretending to be your phone can sneak in.
Apple’s Beats Firmware Update 1B211 patches the flaw. There’s no manual “Update now” button: just keep your Studio Buds in their case, close the lid, make sure they and your iPhone, iPad or Mac are charged and within Bluetooth range. After a little time, the firmware should upgrade itself.
To confirm the update, open Settings > Bluetooth on iOS or iPadOS, tap the info icon next to your Beats Studio Buds and check the version. If it’s 1B211, you’re safe. If it still shows an older release, leave the buds in their case near your Apple device and check back later.
Questions about this article
No questions yet.