Junglewise Threat Intelligence

CVE-2025-20701: Airoha Bluetooth audio SDK unauthorized pairing and eavesdropping

CVE-2025-20701 · Severity: high · CVSS 8.8 · Published 2025-08-04

Vendors: Apple.

Executive brief

A security flaw in Airoha Bluetooth audio software allows unauthorized devices to pair with headphones and speakers without the owner's knowledge or consent. This vulnerability, which affects various chipsets including those used in some Beats products, could allow an attacker within Bluetooth range to eavesdrop on conversations through the device's microphone. No user interaction is required for an attacker to exploit this flaw and gain unauthorized access to the audio stream.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Airoha Bluetooth audio SDK during the BR/EDR pairing process. The flaw allows a remote attacker within Bluetooth range to initiate and complete a pairing request without the legitimate user's consent or interaction, even when the device is in a non-pairing mode. Successful exploitation results in an escalation of privilege, allowing the attacker to access sensitive functions such as the device microphone. The vulnerability affects Airoha AB156x, AB157x, AB158x, and AB159x series chipsets. Apple has released firmware update 1B211 for Beats Studio Buds to address this issue.

Affected products

  • Airoha Technology Corp. IoT SDK for BT audio v5.5.0 and earlier
  • Airoha Technology Corp. AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier
  • Apple Beats Studio Buds Firmware Before 1B211

Timeline

  • 2025-08-04: advisory: Initial advisory published by Airoha/MediaTek
  • 2025-08-04: disclosed: CVE-2025-20701 published to NVD
  • 2026-06-16: patched: Apple released Beats Firmware Update 1B211 to address the issue in Beats Studio Buds

References