Overview
- Apple published Beats firmware 1B211 on June 16, 2026 to patch a Bluetooth vulnerability tracked as CVE-2025-20701.
- The flaw could let an attacker within Bluetooth range listen through a Studio Buds microphone only when the earbuds were not yet paired and actively seeking a connection.
- Researchers Dennis Heinze and Frieder Steinmetz of ERNW reported the issue and showed it stems from a missing authentication weakness in shared open-source code.
- Beats firmware installs automatically when Studio Buds are in their charging case, charging, and within Bluetooth range of a paired iPhone, iPad, or Mac; Android users receive updates through the Beats app.
- Users can check the patch by viewing the earbuds’ firmware version in Bluetooth settings and should keep earbuds in their case and near a paired device to receive the update; the open-source root cause means other devices and projects may need similar fixes.