The images in this article were generated with artificial intelligence. How we publish
Apple has published a firmware update for the Beats Studio Buds wireless headphones that fixes a high-severity vulnerability (CVE-2025-20701) in the Bluetooth audio SDK of Airoha that allowed to match devices without user consent and, in some cases, to remotely spy on the microphone while the headphone was in matching search mode. The update indicated as Beats Firmware 1B211 must be installed immediately on affected devices because the operation does not require user interaction beyond being within the Bluetooth range of the target.
The technical root of the problem is an incorrect authorization in the Bluetooth battery software of the Airoha chips; researchers from ERNW GmbH reported these types of failures and showed that with these vulnerabilities an attacker can read and write on the RAM and device flash, take full control of the headphones and, as a result, attack the paired phone or keep listening persistent. That the attack only works with physical proximity (Bluetooth range) makes it practical for surveillance scenarios in public spaces or meetings. For more information on the work published by researchers on the ERNW website: ERNW GmbH.

In parallel to these corrections in the headphone ecosystem, the European company Paradigm Shift released a BootROM explosion called usbliter8 that affects the Apple A12 and A13 Chip SequreROM. The explosion takes advantage of a failure in the SoC USB hardware driver that allows a underflow condition in a package buffer, which under certain conditions allows you to inject and run code at the lowest level of boot. The vulnerabilities of the BootROM level are especially serious because the code is immutable: they cannot be corrected with a traditional software patch; the most effective mitigation is to migrate to more recent hardware if complete protection is needed against this vector.
Paradigm Shift points out that the problem seems to reside in the USB driver settings of those chips (A12 and A13) and not in the updated firmware, and that later generations (A14) show configurations that prevent exploitation. Although usbliter8 does not directly compromise the SEP (Secure Enclave Processor), open a code access on SecureROM greatly increases the surface for attacks that can undermine the device's confidence chain. The very nature of BootROM's vulnerabilities makes them significantly comparable to previous public exploits such as checkm8.
The practical implications for the average user are double and require different actions. On the one hand, Bluetooth peripherals - headphones, speakers, smartwatches - can be spying and pivoting vectors to the phone if they use vulnerable firmware; on the other hand, BootROM bugs on phones involve a permanent risk that is only eliminated by changing hardware or applying physical and policy mitigation in the device environment.

As concrete and applicable recommendations right now: update the firmware of your headphones and other Bluetooth peripherals as soon as the manufacturer publishes the correction (in the case of Beats, install the 1B211 version and confirm the version from the corresponding application), avoid leaving devices in undiscovered or matching mode in public places, and disable Bluetooth when not using it. For phones, keep the operating system up-to-date, activate security options such as USB-restricted mode and use trusted cables and chargers. Since the vulnerabilities of BootROM are not parked via software, consider replacing high-risk devices with A12 / A13 chips if you handle extremely sensitive information.
Organizations and administrators should add additional controls: monitor and distribute updated firmware at inventory level, block unmanaged ports and accessories, and implement MDM policies that deactivate unnecessary functionalities (e.g., Bluetooth discovery). For private users, a practical pattern is not to use company headphones or provided for sensitive meetings and to regularly review the manufacturer's safety warnings and bulletins.
The joint disclosure of these failures recalls that the security of the hardware and firmware supply chain is critical and that wireless connectivity and peripheral controllers are privileged entry points for local attackers. Digital hygiene - updating, reducing wireless exposure and controlling physical access - remains the most effective defensive in the face of such threats. To follow official communications and security bulletins, see the manufacturer and the security community resources, such as Apple's general security notice and research publications: Apple - About Apple security updates and the Paradigm Shift page where your research and concept tests are detailed: Paradigm Shift.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...