Close Menu
    What's Hot

    German electricity grid equipment maker SGB-SMIT in early IPO talks

    Joe Joyce insists a rematch with former rival and now WBO world champion Daniel Dubois is ‘an attractive option’ | Boxing News

    Today at Royal Ascot: Aidan O’Brien pair Precise and True Love star in Coronation Stakes clash | Racing News

    Facebook X (Twitter) Instagram
    Trending
    • German electricity grid equipment maker SGB-SMIT in early IPO talks
    • Joe Joyce insists a rematch with former rival and now WBO world champion Daniel Dubois is ‘an attractive option’ | Boxing News
    • Today at Royal Ascot: Aidan O’Brien pair Precise and True Love star in Coronation Stakes clash | Racing News
    • Decision-making, strategy key early on at 2026 U.S. Open in Round 1
    • The US says ASML’s top chip tool may be in China. ASML says it isn’t
    • Fable 5 crossed a line the world was not ready for
    • Orban’s Defeat Changes the Strongman’s Playbook
    • Amazon hopes to challenge Nvidia more directly by selling its AI chips
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

    adminBy adminJune 19, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 19, 2026Mobile Security / Vulnerability

    Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

    Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.

    The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio device without user consent.

    Successful exploitation of the flaw could lead to remote escalation of privilege without requiring any additional execution privileges or user interaction. The issue has been addressed in Beats Firmware Update 1B211.

    “An attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired and actively seeking pair requests,” Apple said in an advisory released this week.

    Details of the vulnerability first emerged in June 2025 when ERNW GmbH researchers Dennis Heinze and Frieder Steinmetz flagged it alongside two other flaws in Airoha SoCs (CVE-2025-20700 and CVE-2025-20702) at the TROOPERS security conference in Germany. Similar patches were released by Jabra in December 2025.

    Cybersecurity

    “In most cases, these vulnerabilities allow attackers to fully take over the headphones via Bluetooth. No authentication or pairing is required,” the researchers noted at the time. “The vulnerabilities can be triggered via Bluetooth BR/EDR or Bluetooth Low Energy (BLE). Being in Bluetooth range is the only precondition. It is possible to read and write the device’s RAM and flash.”

    “These capabilities also allow attackers to hijack established trust relationships with other devices, such as the phone paired to the headphones. These capabilities allow for multiple attack scenarios.”

    New Unpatchable Exploit Discovered in Apple’s A12 and A13 Chips

    The disclosure comes as Paradigm Shift disclosed a novel iPhone SecureROM (aka BootROM) vulnerability impacting Apple’s A12 and A13 chips, in addition to a proof-of-concept (PoC) exploit codenamed usbliter8.

    “The exploit leverages both a hardware bug in the USB controller and a specific configuration flaw present in the device firmware,” the European cybersecurity company said. “As these vulnerabilities reside in immutable code, affected users should be aware that migrating to newer hardware remains the most effective mitigation.”

    At a high level, the exploit works by leveraging a flaw in the USB controller built into Apple SoCs. The controller uses a memory buffer to store SETUP and OUT packets transmitted at the start of data transfer. The research found that it’s possible to trigger a buffer underflow primitive by taking advantage of the fact that the controller also accepts smaller packets, effectively allowing for malicious code injection and execution under certain conditions. 

    The problem, Paradigm Shift noted, is likely rooted in the USB controller hardware itself, not in Apple’s software. The A11 chip is not susceptible to the vulnerability, while A12 and A13 are confirmed to be susceptible.

    Cybersecurity

    “The difference is that the A11 USB driver manually resets the DMA address to its initial value after receiving each packet,” the company said. “On A12 and A13, USB DART is configured in bypass mode, allowing us to overwrite SRAM data freely. In contrast, A14 and later generations appear to configure the DART correctly in SecureROM, making the vulnerability unexploitable.”

    The usbliter8 exploit is comparable to checkm8, the publicly known BootROM exploit of this kind that impacted all iOS devices ranging from iPhone 4s (A5 chip) to iPhone 8 and iPhone X (A11 chip).

    “The usbliter8 exploit demonstrates that even on more recent SecureROM generations, including those protected by Pointer Authentication, subtle hardware bugs can still be leveraged to achieve full code execution and break the chain of trust,” Paradigm Shift said.

    “The security of the BootROM is critical: vulnerabilities at this level can compromise the integrity of the entire device. Although usbliter8 doesn’t affect SEP itself, it opens up wider attack vectors to compromise the Secure Enclave.”

    Apple Attackers Beats Buds flaw letting Microphone nearby Patches Spy Studio
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleHannah Pingree and Bobby Charles Will Face Off in Maine Governor’s Race
    Next Article Barret Zoph is out at OpenAI again after just five months
    admin
    • Website

    Related Posts

    INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

    June 19, 2026

    Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

    June 18, 2026

    F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

    June 18, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    German electricity grid equipment maker SGB-SMIT in early IPO talks

    Joe Joyce insists a rematch with former rival and now WBO world champion Daniel Dubois is ‘an attractive option’ | Boxing News

    Today at Royal Ascot: Aidan O’Brien pair Precise and True Love star in Coronation Stakes clash | Racing News

    Decision-making, strategy key early on at 2026 U.S. Open in Round 1

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by