- What: Apple releases security update for Beats Studio Buds
- Impact: Users with vulnerable earbuds may be at risk of eavesdropping
IoT Apple releases security update for Beats Studio Buds vulnerability June 18, 2026 Share By SC Staff (Adobe Stock) As reported by Bleeping Computer, Apple has issued a security update to address a vulnerability affecting Beats Studio Buds wireless earbuds. This flaw could potentially allow attackers within Bluetooth range to eavesdrop on user conversations. The vulnerability, identified as CVE-2025-20701, was discovered by researchers Dennis Heinze and Frieder Steinmetz of ERNW GmbH. It stems from a missing authentication weakness in the Bluetooth BR/EDR radio of the Airoha system-on-a-chip (SoCs) used in the earbuds. Attackers in close proximity could exploit this flaw to listen through the microphone of an unpaired device actively seeking pairing requests. Apple has patched this issue with Beats Firmware Update 1B211, which will be delivered automatically to vulnerable devices. When chained with two other vulnerabilities (CVE-2025-20700 and CVE-2025-20702), attackers could also hijack the Bluetooth Hands-Free Profile to issue commands to a phone. While the researchers noted that real-world attacks are complex and require significant technical sophistication and physical proximity, they could allow attackers to take over the headphones, read device memory, retrieve call history, and even initiate calls. Source: Bleeping Computer SC Staff Related IoT Thousands of live cameras stream with no authentication, exposing security risks SC Staff June 12, 2026 A recent analysis by Mysterium VPN revealed that over 21,000 live cameras are accessible online without any login credentials or security barriers. IoT Researcher finds Bright Data iOS SDK turns smart TVs into web-scraping nodes SC Staff June 8, 2026 Bright Data, formerly Luminati, operates a large residential proxy network, with a portion sourced from an SDK embedded in free applications. IoT Dragos acquires Phosphorus to enhance industrial cybersecurity SC Staff June 1, 2026 The acquisition aims to integrate Phosphorus' platform, which identifies connected devices, assesses exposures, and automates remediation, into Dragos' offerings. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds