threat-intel
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
Critical
Summary
A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization within the Airoha Bluetooth audio SDK, enabling unauthorized pairing and microphone access. Simultaneously, Paradigm Shift discovered a separate, more critical vulnerability in Apple’s A12 and A13 chips, offering a path to full device control.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
