HomeSecurityBluetooth vulnerabilities affect popular audio devices

Bluetooth vulnerabilities affect popular audio devices

Cybersecurity researchers have identified three new vulnerabilities in Bluetooth chipsets that affect popular audio devices, allowing malicious users to intercept or access sensitive information, such as contact lists and call history.

Bluetooth Vulnerabilities

The flaws are found in Airoha systems-on-a-chip (SoC) used in True Wireless Stereo (TWS) headphones and affect at least 29 devices from 10 leading manufacturers: Beyerdynamic, Bose, Sony, Marshall, Jabra, JBL, Jlab, EarisMax, MoerLabs and Teufel. The list includes headphones, speakers and wireless microphones.

Technical presentation and proof-of-concept at the TROOPERS conference

The findings were announced at the TROOPERS security conference in Germany by the ERNW research team , which presented a working exploit code that can intercept audio played on vulnerable devices in real time.

See also: MOVEit Transfer: System scanning and vulnerability exploitation

The vulnerabilities identified are:

  • CVE-2025-20700 (score 6.7/10): Lack of authentication in GATT services.
  • CVE-2025-20701 (score 6.7/10): Similar vulnerability in Bluetooth BR/EDR.
  • CVE-2025-20702 (score 7.5/10): High severity vulnerability in a custom protocol, which provides unexpected capabilities to attackers.

Although the issues require physical proximity (due to Bluetooth's limited range) and technical expertise, their implications can be significant. The researchers revealed that, in addition to simply listening to audio, an attacker can hijack the connection between a mobile phone and a Bluetooth audio device and use the Bluetooth Hands-Free Profile (HFP) to send commands to the phone.

"The range of available commands depends on the mobile operating system, but all major platforms support at least initiating and receiving calls," ERNW reported.

The researchers were able to make a call to a number by extracting the Bluetooth link keys from the memory of a vulnerable device.

According to their research, depending on the phone's configuration, an attacker could also retrieve call history and contacts. They were also able to initiate a call and "successfully monitor conversations or audio within range of the phone."

See also: Cisco: Critical vulnerabilities in Cisco Identity Services Engine (ISE)

Additionally, the firmware of the vulnerable device could potentially be rewritten to allow remote code execution, thus facilitating the development of a wormable exploit capable of spreading to multiple devices.

What this means for users:

If you have a Bluetooth audio device from a well-known brand, it may be affected. Although exploitation requires specialized knowledge and proximity, the implications can be serious, especially in professional environments or public places.

Bluetooth vulnerabilities affect popular audio devices

Users are invited to:

  • Update the firmware of their devices, if available.
  • Avoid Bluetooth connections in public places.
  • They monitor for safety announcements from manufacturers.

Updated SDK Available — Firmware Update Delays

Airoha has already distributed a new Software Development Kit (SDK) to its customers that includes fixes and mitigations. At the same time, manufacturers have begun developing firmware updates for devices using the affected Bluetooth chipsets.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

However, according to the German edition of Heise, more than half of the affected devices had their last firmware update before May 27 — that is, before the new SDK was released by Airoha. This may mean that many devices are currently vulnerable until the update process by manufacturers.

See also: IBM i vulnerability allows privilege escalation

The threat is technically serious and highlights how fragile security can be on consumer devices, even from large companies. However, we are not talking about a widespread ransomware-like threat that could massively affect the population. Instead, this revelation reminds us of the need for timely updates, transparency, and a redesign of how we understand security in the Bluetooth ecosystem.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS