Particle.news

Apple Releases Beats Studio Buds Patch for Bluetooth Eavesdropping Flaw

The update fixes a bug in widely used open-source Bluetooth code that let nearby attackers exploit unpaired earbuds to access the microphone.

Overview

  • Apple published Beats firmware 1B211 on June 16, 2026 to patch a Bluetooth vulnerability tracked as CVE-2025-20701.
  • The flaw could let an attacker within Bluetooth range listen through a Studio Buds microphone only when the earbuds were not yet paired and actively seeking a connection.
  • Researchers Dennis Heinze and Frieder Steinmetz of ERNW reported the issue and showed it stems from a missing authentication weakness in shared open-source code.
  • Beats firmware installs automatically when Studio Buds are in their charging case, charging, and within Bluetooth range of a paired iPhone, iPad, or Mac; Android users receive updates through the Beats app.
  • Users can check the patch by viewing the earbuds’ firmware version in Bluetooth settings and should keep earbuds in their case and near a paired device to receive the update; the open-source root cause means other devices and projects may need similar fixes.