Apple has released a firmware update for AirPods , as a Bluetooth vulnerability could allow a malicious actor to gain access to the headphones.

Tracking as CVE-2024-27867, the authentication issue affects AirPods (2nd generation and later), AirPods Pro (all models), AirPods Max, Powerbeats Pro and Beats Fit Pro.
Read also: Botnet exploits vulnerability in Zyxel NAS devices
"When your headphones attempt to connect to one of your previously paired devices, a hacker within Bluetooth range could spoof the intended device and gain access to your headphones," Apple warned in an advisory on Tuesday.
In other words, a hacker in close proximity could exploit this vulnerability to eavesdrop on private conversations. Apple stated that the issue has been addressed with improved state management.
Jonas Dreßler appears to have discovered and reported the flaw. The issue has been fixed with the firmware updates AirPods 6A326, AirPods 6F8 and Beats 6F8.
Following the iPhone manufacturer's announcement of updates to visionOS (version 1.2), 21 bugs are being fixed, including seven flaws in the WebKit browser engine.
See more: Polyfill.io: Attack affects over 100,000 websites
One of the issues concerns a logic flaw (CVE-2024-27812) that could lead to denial-of-service (DoS) attacks when processing web content. The problem was fixed with improved file handling, said security Ryan Pickren. Pickren, who reported the vulnerability, described it as the “world’s first spatial computing hack,” capable of “bypassing all warnings and forcefully filling your space with an arbitrary number of moving 3D objects” without user interaction.
The vulnerability exploits Apple's weakness, aiming to implement the licensing model when using the ARKit Quick Look feature, so that three-dimensional objects are rendered in the victim's space. Additionally, the moving objects remain active even after exiting Safari, as they are managed by a separate application.

Read more: New AirPods Pro beta feature optimizes noise cancellation
“It also doesn’t require the user to click on this tag,” Pickren said. “Programmatically triggering it in JavaScript, such as using document.querySelector('a').click(), is no problem. This means we can trigger an unlimited number of 3D objects, animations, and sound effects without any user interaction .”
Source: thehackernews
