惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
V
Visual Studio Blog
雷峰网
雷峰网
博客园_首页
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
小众软件
小众软件
D
Docker
P
Proofpoint News Feed
B
Blog
Vercel News
Vercel News
B
Blog RSS Feed
U
Unit 42
月光博客
月光博客
The GitHub Blog
The GitHub Blog
Apple Machine Learning Research
Apple Machine Learning Research
Y
Y Combinator Blog
I
InfoQ
Recent Announcements
Recent Announcements

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Apple Beats Studio Buds Vulnerability Allows Hackers to E...
Abinaya · 2026-06-23 · via Cyber Security News

Apple has addressed a high-severity vulnerability in the Beats Studio Buds that could allow nearby attackers to eavesdrop on users via the device’s microphone, even when the earbuds are not actively paired.

Apple fixed the Bluetooth vulnerability in Beats Firmware Update 1B211, released on June 16, 2026, addressing a flaw that could be exploited by attackers within wireless range.

The vulnerability, tracked as CVE-2025-20701, was discovered by security researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH.

Apple Beats Studio Buds Vulnerability

The flaw impacts Beats Studio Buds and stems from a weakness in open-source code integrated into Apple’s software ecosystem.

Apple confirmed that affected devices could unintentionally expose microphone audio when actively seeking pairing connections.

In practical terms, this means an attacker positioned within Bluetooth range could potentially connect to the earbuds without authorization and access live audio input.

The attack does not require prior pairing, making it particularly concerning in public environments such as offices, airports, or cafes.

Apple has not disclosed detailed technical specifics of the exploit, in line with its standard policy of limiting information until patches are widely deployed.

However, the nature of the vulnerability suggests improper authentication or validation during the Bluetooth pairing process. The primary risk associated with CVE-2025-20701 is unauthorized audio surveillance.

Since the vulnerability allows access to the microphone, attackers could potentially capture sensitive conversations without the user’s knowledge.

The attack is limited by proximity, as the threat actor must be within Bluetooth range, typically around 10 meters.

Despite this limitation, the vulnerability is considered high severity due to the sensitivity of the data exposed and the lack of user interaction required.

While there is no evidence of active exploitation, security experts recommend updating immediately, as Apple has patched the Bluetooth vulnerability in Beats Firmware Update 1B211.

The update is automatically delivered to Beats Studio Buds when they are connected to an iPhone, iPad, or Mac and within Bluetooth range.

Users can verify their firmware version through device settings:

On iPhone or iPad: Go to Settings > Bluetooth, then tap the info icon next to the earbuds.

On Mac: Go to System Settings > Bluetooth and select the connected device.

Ensuring devices are updated is the primary mitigation step. Users are also advised to disable Bluetooth when not in use and avoid pairing devices in untrusted environments.

This vulnerability highlights ongoing risks associated with wireless communication protocols, particularly Bluetooth. As more devices rely on seamless pairing and always-on connectivity, the attack surface continues to expand.

Apple credited the third-party researchers and noted that the vulnerability originates from open-source components, emphasizing the shared responsibility across the software supply chain.

Users are encouraged to monitor Apple’s official security updates page for further advisories and ensure all connected devices remain up to date.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.