Apple patches eavesdropping vulnerability in Beats Studio Buds



Security firm Sentinel One has a deeper dive into CVE-2025-20701 here.

Heinze and Steinmetz said last year that the full chain of attacks gave attackers the ability to do other malicious things, including retrieving call history and contacts, and even calling arbitrary numbers. Many of those capabilities are dependent on the specific devices being paired, since the functionality built into them differs from platform to platform.

Devices affected by the Airoha vulnerabilities are by no means alone. In January, researchers disclosed WhisperPair, a series of vulnerabilities that allows an attacker to hijack Bluetooth devices connected through Google Fast Pair, a proprietary protocol belonging to the company. Besides eavesdropping, attackers can exploit the WhisperPair flaws to geolocate devices. The vulnerabilities affect more than a dozen devices from 10 manufacturers, including Sony, Nothing, JBL, OnePlus, and Google itself.

There are few, if any, reports of Bluetooth vulnerabilities like these being actively exploited in the wild. The complexity of such attacks is often high, and an attacker has to continually stay within Bluetooth range of a target while utilizing the exploit. People who think they may be targeted by such attacks should turn off Bluetooth in devices whenever they’re not needed, and remain aware of the risks when Bluetooth is enabled.



Source link

  • Related Posts

    The CEO of Allbirds’ new AI biz has a plan, but no employees

    Call it a startup with a sole founder and a very large seed round, but what’s next is less clear. Source link

    EFF Joins 60+ Groups Urging the UK to Halt Face Estimation at the Border

    This week, EFF joined Foxglove, Human Rights Watch, and 60 other organizations in writing to the UK’s Minister of State for Border Security and Asylum, Alex Norris, raising serious concern…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Flu outbreak among Air Force recruits at Joint Base San Antonio after Hegseth ends mandatory flu vaccine

    Flu outbreak among Air Force recruits at Joint Base San Antonio after Hegseth ends mandatory flu vaccine

    The CEO of Allbirds’ new AI biz has a plan, but no employees

    The CEO of Allbirds’ new AI biz has a plan, but no employees

    Shop the Best Anti-Trend Embroidered Dresses From Zara and H&M

    Shop the Best Anti-Trend Embroidered Dresses From Zara and H&M

    Iran deal brings little relief for inflation-wary central banks

    Can sunlight make you sneeze?

    Can sunlight make you sneeze?

    Fire aboard fishing boat prompts board to send investigators to Nova Scotia

    Fire aboard fishing boat prompts board to send investigators to Nova Scotia