Bats Studio Svulnerable Buds and Apple BootROM open doors to nearby espionage

Author: Published 4 min de lectura 246 reading

The images in this article were generated with artificial intelligence. How we publish

Apple has published a firmware update for the Beats Studio Buds wireless headphones that fixes a high-severity vulnerability (CVE-2025-20701) in the Bluetooth audio SDK of Airoha that allowed to match devices without user consent and, in some cases, to remotely spy on the microphone while the headphone was in matching search mode. The update indicated as Beats Firmware 1B211 must be installed immediately on affected devices because the operation does not require user interaction beyond being within the Bluetooth range of the target.

The technical root of the problem is an incorrect authorization in the Bluetooth battery software of the Airoha chips; researchers from ERNW GmbH reported these types of failures and showed that with these vulnerabilities an attacker can read and write on the RAM and device flash, take full control of the headphones and, as a result, attack the paired phone or keep listening persistent. That the attack only works with physical proximity (Bluetooth range) makes it practical for surveillance scenarios in public spaces or meetings. For more information on the work published by researchers on the ERNW website: ERNW GmbH.

Bats Studio Svulnerable Buds and Apple BootROM open doors to nearby espionage
Image generated with IA.

In parallel to these corrections in the headphone ecosystem, the European company Paradigm Shift released a BootROM explosion called usbliter8 that affects the Apple A12 and A13 Chip SequreROM. The explosion takes advantage of a failure in the SoC USB hardware driver that allows a underflow condition in a package buffer, which under certain conditions allows you to inject and run code at the lowest level of boot. The vulnerabilities of the BootROM level are especially serious because the code is immutable: they cannot be corrected with a traditional software patch; the most effective mitigation is to migrate to more recent hardware if complete protection is needed against this vector.

Paradigm Shift points out that the problem seems to reside in the USB driver settings of those chips (A12 and A13) and not in the updated firmware, and that later generations (A14) show configurations that prevent exploitation. Although usbliter8 does not directly compromise the SEP (Secure Enclave Processor), open a code access on SecureROM greatly increases the surface for attacks that can undermine the device's confidence chain. The very nature of BootROM's vulnerabilities makes them significantly comparable to previous public exploits such as checkm8.

The practical implications for the average user are double and require different actions. On the one hand, Bluetooth peripherals - headphones, speakers, smartwatches - can be spying and pivoting vectors to the phone if they use vulnerable firmware; on the other hand, BootROM bugs on phones involve a permanent risk that is only eliminated by changing hardware or applying physical and policy mitigation in the device environment.

Bats Studio Svulnerable Buds and Apple BootROM open doors to nearby espionage
Image generated with IA.

As concrete and applicable recommendations right now: update the firmware of your headphones and other Bluetooth peripherals as soon as the manufacturer publishes the correction (in the case of Beats, install the 1B211 version and confirm the version from the corresponding application), avoid leaving devices in undiscovered or matching mode in public places, and disable Bluetooth when not using it. For phones, keep the operating system up-to-date, activate security options such as USB-restricted mode and use trusted cables and chargers. Since the vulnerabilities of BootROM are not parked via software, consider replacing high-risk devices with A12 / A13 chips if you handle extremely sensitive information.

Organizations and administrators should add additional controls: monitor and distribute updated firmware at inventory level, block unmanaged ports and accessories, and implement MDM policies that deactivate unnecessary functionalities (e.g., Bluetooth discovery). For private users, a practical pattern is not to use company headphones or provided for sensitive meetings and to regularly review the manufacturer's safety warnings and bulletins.

The joint disclosure of these failures recalls that the security of the hardware and firmware supply chain is critical and that wireless connectivity and peripheral controllers are privileged entry points for local attackers. Digital hygiene - updating, reducing wireless exposure and controlling physical access - remains the most effective defensive in the face of such threats. To follow official communications and security bulletins, see the manufacturer and the security community resources, such as Apple's general security notice and research publications: Apple - About Apple security updates and the Paradigm Shift page where your research and concept tests are detailed: Paradigm Shift.

Coverage

Related

More news on the same subject.