Bluetooth gap: Apple Beats headphones allowed secret eavesdropping

Are the wireless Beats Studio Buds part of your daily equipment and is someone secretly listening in? A fatal security hole allows attackers to do exactly this eavesdropping attack, while Apple only distributes the saving update in a hidden manner.
Danger due to Bluetooth gap
A critical vulnerability in the Beats Studio Buds wireless earbuds allowed attackers to listen in via the built-in microphone. The vulnerability (CVE-2025-20701) affects 2021 models and can be exploited if an attacker is within Bluetooth range. Devices are particularly vulnerable if they are not yet paired and are actively searching for connections. But there is also a risk with existing connections, for example if attackers establish a connection more quickly when taking it out of the charging case.
Via Apple An update is available with firmware version 1B211 that closes the vulnerability. According to the manufacturer, the cause of the security gap is a bug in a third-party component. Experts assign these to the provider Airoha, a MediaTek subsidiary.
Backgrounds and the updateThe cause is a missing authentication step when establishing the connection. In combination with other vulnerabilities, attackers could theoretically also initiate calls or access stored data such as contact lists. However, such attacks require significant technical expertise. An IT security researcher had already publicly demonstrated the vulnerability around a year ago. It is not known why the patch is only now available. The successor model Beats Studio Buds Plus is apparently not affected.
In contrast to Apple’s AirPods, the Beats Studio Buds do not use their own chip, but rather an audio processor from MediaTek. This improves compatibility with Android devices, but may introduce additional security risks. The update will automatically install once the headphones are connected to an iPhone, iPad or Mac and in the closed charging case. A connected charger can speed up the process. The installed firmware version can be checked in the Bluetooth settings. The affected models are still available in stores.