惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
S
SegmentFault 最新的问题
D
Docker
博客园 - 司徒正美
雷峰网
雷峰网
V
Visual Studio Blog
云风的 BLOG
云风的 BLOG
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - Franky
月光博客
月光博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
The Blog of Author Tim Ferriss
Google DeepMind News
Google DeepMind News
MyScale Blog
MyScale Blog
MongoDB | Blog
MongoDB | Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Apple Beats Studio Buds Vulnerability Allows Hackers to E...
Abinaya · 2026-06-23 · via Cyber Security News

Apple has addressed a high-severity vulnerability in the Beats Studio Buds that could allow nearby attackers to eavesdrop on users via the device’s microphone, even when the earbuds are not actively paired.

Apple fixed the Bluetooth vulnerability in Beats Firmware Update 1B211, released on June 16, 2026, addressing a flaw that could be exploited by attackers within wireless range.

The vulnerability, tracked as CVE-2025-20701, was discovered by security researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH.

Apple Beats Studio Buds Vulnerability

The flaw impacts Beats Studio Buds and stems from a weakness in open-source code integrated into Apple’s software ecosystem.

Apple confirmed that affected devices could unintentionally expose microphone audio when actively seeking pairing connections.

In practical terms, this means an attacker positioned within Bluetooth range could potentially connect to the earbuds without authorization and access live audio input.

The attack does not require prior pairing, making it particularly concerning in public environments such as offices, airports, or cafes.

Apple has not disclosed detailed technical specifics of the exploit, in line with its standard policy of limiting information until patches are widely deployed.

However, the nature of the vulnerability suggests improper authentication or validation during the Bluetooth pairing process. The primary risk associated with CVE-2025-20701 is unauthorized audio surveillance.

Since the vulnerability allows access to the microphone, attackers could potentially capture sensitive conversations without the user’s knowledge.

The attack is limited by proximity, as the threat actor must be within Bluetooth range, typically around 10 meters.

Despite this limitation, the vulnerability is considered high severity due to the sensitivity of the data exposed and the lack of user interaction required.

While there is no evidence of active exploitation, security experts recommend updating immediately, as Apple has patched the Bluetooth vulnerability in Beats Firmware Update 1B211.

The update is automatically delivered to Beats Studio Buds when they are connected to an iPhone, iPad, or Mac and within Bluetooth range.

Users can verify their firmware version through device settings:

On iPhone or iPad: Go to Settings > Bluetooth, then tap the info icon next to the earbuds.

On Mac: Go to System Settings > Bluetooth and select the connected device.

Ensuring devices are updated is the primary mitigation step. Users are also advised to disable Bluetooth when not in use and avoid pairing devices in untrusted environments.

This vulnerability highlights ongoing risks associated with wireless communication protocols, particularly Bluetooth. As more devices rely on seamless pairing and always-on connectivity, the attack surface continues to expand.

Apple credited the third-party researchers and noted that the vulnerability originates from open-source components, emphasizing the shared responsibility across the software supply chain.

Users are encouraged to monitor Apple’s official security updates page for further advisories and ensure all connected devices remain up to date.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.