Security researchers have uncovered severe vulnerabilities in Bluetooth headphones and earbuds using Airoha Systems-on-Chip (SoCs), enabling attackers within Bluetooth range (~10 meters) to compromise devices without requiring full authentication.
The flaws affect products from major brands including Sony, Bose, Marshall, and Jabra, exposing users to eavesdropping, data theft, and device hijacking.
Three critical CVEs facilitate the attacks: CVE-2025-20700 (missing GATT service authentication), CVE-2025-20701 (unauthenticated Bluetooth BR/EDR access), and CVE-2025-20702 (unsecured custom protocol). These allow:
Testing confirmed vulnerabilities across entry-level and flagship models, including:
| Brand | Affected Models |
|---|---|
| Sony | WH-1000XM6, WF-1000XM5, CH-720N, 10+ others |
| Marshall | MAJOR V, MINOR IV, ACTON III, 5 models |
| Bose | QuietComfort Earbuds |
| Jabra | Elite 8 Active |
| JBL | Live Buds 3, Endurance Race 2 |
| The full scope remains unknown due to supply-chain opacity, with some vendors unaware they use Airoha SoCs1. |
Airoha released SDK patches to manufacturers in early June 2025, but no firmware updates are yet available to consumers.
High-risk individuals (journalists, diplomats) should:
The vulnerabilities highlight systemic risks in IoT supply chains, where obscured component origins impede vulnerability management.
While complex attacks require proximity and technical skill, the flaws demonstrate critical infrastructure weaknesses in widely deployed consumer devices.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post Bluetooth Flaws Allow Hackers to Eavesdrop via Headphones and Earbuds appeared first on Cyber Security News.
THE HAGUE, Netherlands (AP) — As U.S. and Israeli forces pounded Iran, and Tehran and its…
Americans don’t trust President Donald Trump when it comes to foreign policy, a Reuters/Ipsos poll…
If you own an old car without Bluetooth and you're looking for a cheap and…
2026 has already seen surges in the cost of RAM and GPUs. Unfortunately, this also…
A gas pump is seen in a vehicle on Nov. 26, 2025, in Austin, Texas.…
A gas pump is seen in a vehicle on Nov. 26, 2025, in Austin, Texas.…
This website uses cookies.