Apple closes critical Bluetooth vulnerability in Beats Studio Buds

Published:


The TL;DR

  • Apple released a very serious Bluetooth bug in the Beats Studio Buds that could have allowed nearby attackers to eavesdrop on conversations using the earbuds’ Bluetooth chip.
  • The vulnerability wasn’t limited to Beats devices — it stems from Airoha Bluetooth chips used by several audio brands, including Sony, Bose, JBL, Marshall, and Jabra.
  • Firmware updates are now available for affected devices, with Apple, Jabra, Bose, and JBL among the manufacturers that have already completed fixes.

Most of us don’t think twice before popping in our earbuds and picking up the phone. Whether you’re discussing work, sharing personal information, or chatting with friends, you probably think those conversations are always between you and the person on the other end. A recently patched Bluetooth vulnerability shows that assumptions aren’t always confirmed, as it could allow nearby attackers to secretly listen in on affected earbuds, including Apple’s Beats Studio Buds.

Rather than targeting smartphones directly, the vulnerability resides in the Bluetooth chips used in a range of wireless audio products. That’s important because these chips aren’t just responsible for connecting your earbuds to the phone — they also control the microphone, process audio, and manage the trusty relationship between your earphones and other devices.

Master & Dynamic MW09 earbuds in the human ear.

The earbuds fit well and are comfortable in my ears.

Security researchers Dennis Heinze and Frieder Steinmetz discovered that Airoha-made Bluetooth chips could be tricked into trusting an unauthorized device. That means an attacker within Bluetooth range can impersonate a previously trusted device and gain access to operations that should have remained private.

That sounds scary, and in the right circumstances, it can be. Researchers have shown that the bug can be misused to listen to audio captured by a connected device’s microphone. According to Apple, this attack may affect devices that actively seek a Bluetooth pairing connection, which adds a significant limitation to how the vulnerability can be exploited.

This means that many manufacturers using the same components may be affected. Airoha chips are found in audio products from several major manufacturers, including Sony, Bose, JBL, Marshall, and Jabra.

The most interesting is where the error lies. Most people think of headphones as simple accessories, but modern earbuds run their own firmware, process audio in real time, manage microphones, and maintain reliable connections with phones, tablets, and laptops. If that firmware contains vulnerabilities, attackers may see the device as an easier target than the device it’s connected to.

The researchers also note that a wider range of attacks may reveal more information without microphone access. Depending on the connected device and platform, attackers may be able to access data such as call logs, contacts, or intercept phone calls. That said, there’s little evidence to suggest that this attack has been actively used on consumers in the real world, and manufacturers have already started rolling out fixes.

JBL Vibe Beam in its charging case.

Christian Thomas / SoundGuys

As far as inexpensive earbuds go, the JBL Vibe Beam has a lot to offer.

Apple has already released firmware updates for affected Beats devices, and other manufacturers have also started releasing patches for affected products. Jabra recently confirmed a fix, too, according to AcousticsBose and JBL also pushed updates.

If you own a pair of Beats Studio Buds, it’s worth checking that your firmware is up to date. On an iPhone, you can do that by opening Settings, going to Bluetooth, and clicking the info button next to your earbuds.

The risk to most users remains very low. Exploiting the vulnerability is not as simple as sending a malicious link or launching a remote attack. An attacker would need to be physically close to the target and have the technical knowledge necessary to take it down.

Still, the incident serves as a useful reminder that even gadgets we don’t often think about in terms of security can be attack sites. And as those devices get smarter, keeping their firmware up to date is just as important as installing the latest update on your smartphone.

Thank you for being a part of our community. Read our Comment Policy before posting.

Related articles

spot_img

Recent articles

spot_img