Beats Studio Buds Pick Up Patch for Bluetooth Pairing Flaw Rated 8.8

An Airoha SDK authorization bug let attackers within range pair without consent. Apple has shipped a firmware fix.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
Beats Studio Buds Pick Up Patch for Bluetooth Pairing Flaw Rated 8.8
Share

Key points

  • CVE-2025-20701 carries a CVSS score of 8.8 and sits in the Airoha Bluetooth audio SDK.
  • The flaw allows a Bluetooth audio device to be paired without user consent.
  • Beats Studio Buds and Studio Buds+ owners are affected.
  • The patch arrives as a firmware update pushed through a paired iOS or Android device.
  • No public evidence of exploitation in the wild has emerged.

What does this flaw actually do?

Apple has pushed a firmware update for the Beats Studio Buds line, closing a Bluetooth flaw that could let an attacker in radio range pair with the earbuds without the owner's knowledge. The bug, CVE-2025-20701, scores 8.8 on the CVSS scale. It sits in the Airoha Bluetooth audio SDK, a chipset-vendor codebase that ships across many consumer audio products, and stems from incorrect authorization handling during pairing.

That's the kind of primitive that turns earbuds into a covert listening post. Once paired, an attacker can pipe audio through the device, and the Studio Buds line includes microphones for calls and voice assistants, so the exposure isn't theoretical.

Should you worry about range?

Exploitation requires proximity. Bluetooth ranges in consumer scenarios typically cap around 10 metres, though directional antennas can extend that. Apple hasn't attributed discovery in its advisory, and there's no public indication the flaw has been exploited.

Who is affected and how do you get the fix?

Owners of Beats Studio Buds and Studio Buds+ need this patch. It arrives as a firmware update pushed through a paired iOS or Android device, so users don't install it manually. Keep the buds connected to a recently updated phone for a day or two, then confirm the firmware string in your device's Bluetooth settings. Enterprise teams issuing Beats hardware should treat this as a managed-device patch cycle rather than a consumer inconvenience.

Why does one SDK bug hit so many brands?

Researchers at ERNW flagged a broader set of Airoha-related issues earlier in 2025, touching earbuds and headphones across multiple brands, with the shared chipset providing the common attack surface. Apple's Beats fix is part of that downstream cleanup. A single authorization bug in one audio SDK ripples through vendors that share nothing else, and more Airoha-linked CVEs are likely before the year's out. That's the supply-chain story worth watching here, not just this one patch.

© 2026 Threat Vectr