Beats Studio Buds Pick Up Patch for Bluetooth Pairing Flaw Rated 8.8
An Airoha SDK authorization bug let attackers within range pair without consent. Apple has shipped a firmware fix.

Apple has pushed a firmware update for its Beats Studio Buds line, closing a Bluetooth flaw that could let an attacker in radio range pair with the earbuds and listen in through the device microphone.
The bug is tracked as CVE-2025-20701 and carries a CVSS score of 8.8. It sits in the Airoha Bluetooth audio SDK — the same chipset-vendor codebase that ships inside a long list of consumer audio products — and stems from incorrect authorization handling during pairing.
The practical effect: a Bluetooth audio device can be paired without the user's consent.
That is the kind of primitive that turns a pair of earbuds into a covert listening post. Once paired, an attacker can pipe audio, and on devices with onboard microphones, capture it. The Studio Buds line includes microphones for calls and voice assistants.
This is not the first time Airoha's SDK has surfaced in vulnerability disclosures this year. Researchers at ERNW flagged a broader set of Airoha-related issues earlier in 2025 affecting earbuds and headphones from multiple brands, with the chipset family providing the common attack surface. Apple's fix for the Beats line is part of the downstream cleanup.
Exploitation requires proximity. Bluetooth Low Energy and Classic ranges typically cap out around 10 meters in consumer scenarios, though directional antennas can extend that. There is no public indication the flaw has been exploited in the wild, and Apple has not attributed discovery in its short advisory.
Who is affected: owners of Beats Studio Buds and Studio Buds+. The patch is delivered as a firmware update pushed through paired iOS or Android devices, which means users do not install it manually so much as keep the buds in range of a phone with the Beats or Apple settings flow active. Firmware updates on AirPods-family hardware have historically been opaque — users often cannot confirm the version without digging into Bluetooth device info.
Advice for users is short. Keep the buds connected to a recently updated phone for a day or two and check the firmware string in your device's Bluetooth settings. Enterprise environments that issue Beats hardware as a perk should treat this as a managed-device patch cycle, not a consumer nuisance.
The wider story here is supply-chain. A single audio SDK shared across vendors means a single authorization bug ripples through brands that have nothing else in common. Expect more Airoha-linked CVEs to land before the year is out.



