惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
有赞技术团队
有赞技术团队
H
Help Net Security
V
Visual Studio Blog
F
Fortinet All Blogs
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 司徒正美
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
L
LangChain Blog
N
Netflix TechBlog - Medium
罗磊的独立博客
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
Hugging Face - Blog
Hugging Face - Blog
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
Recent Announcements
Recent Announcements

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdr...
Deeba Ahmed · 2026-06-23 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Apple has fixed a flaw in its Beats Studio Buds wireless headphones that allowed hackers to use the built-in microphone to listen to your private conversations without your knowledge.

According to Apple’s official advisory, the issue is tracked as CVE-2025-20701, and was identified by researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH security firm.

Heinze and Steinmetz discovered that the bug exists in the open-source code of a system called the Airoha Bluetooth audio SDK. For your information, this system helps run the earbuds, and the issue happens when the headphones are turned on but aren’t connected to a phone or computer.

Vulnerability Explained

What happens in this scenario is that the earbuds look for a new connection. That’s when any hacker in proximity can strike. All they have to do is link to the device, and this doesn’t even need the user’s permission. The software cannot check or verify who is connecting, so the hacker can easily eavesdrop on your conversations.

However, this trick requires some prerequisites, such as the hacker must be within a standard Bluetooth range of about 10 metres. During the testing phase, researchers chained this bug with two other flaws.

The first issue, CVE-2025-20700, allows an unauthenticated attacker to connect to the earbuds using Bluetooth Low Energy, whereas the second issue, CVE-2025-20702, helps them evade security and access internal management settings.

Combining them allowed researchers to use the Bluetooth Hands-Free Profile feature and look at call histories or contact lists, and dial numbers. However, real attacks are very hard to carry out, research reveals, because they require expert skills and physical closeness to the person.

How to Get the Update

Apple fixed the bug on 16 June by releasing Beats Firmware Update 1B211. You don’t need to click anything to install this fix as the earbuds update by themselves when they are in their charging case, plugged into power, and placed near an iPhone, iPad, or Mac with Bluetooth turned on. Android users need to get the patch through the official Beats app.

You can also confirm if your earbuds are updated. Just open the Bluetooth settings and check the version number. Consider the patch as active if the version is 1B211. However, it is still a good idea to turn off Bluetooth when not in use to keep your devices safe.

Photo by Lalith Sai Thomala on Unsplash