INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Apple Patches Beats Studio Buds Flaw Allowing Nearby Attackers Eavesdrop

| 2026-06-22 17:57 HIGH LOW VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On June 16, Apple fixed a flaw in its Beats Studio Buds wireless headphones that allowed hackers to eavesdrop on users' private conversations without their knowledge. The issue was identified by researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH security firm as CVE-2025-20701. This vulnerability exists when the earbuds are turned on but not connected to a phone or computer, allowing hackers within 10 meters of proximity to connect and eavesdrop on conversations without user permission. Apple released Beats Firmware Update 1B211 to fix the bug, which can be automatically updated by earbuds in their charging case with Bluetooth enabled when paired with an iPhone, iPad, or Mac; Android users need to get the patch through the official Beats app.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-20700, CVE-2025-20702 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Password Policies (ATT&CK mitigation for Credential Stuffing): Refer to NIST guidelines when creating password policies. • User Account Management (ATT&CK mitigation for Credential Stuffing): Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-20700CVE-2025-20700 CVE-2025-20702CVE-2025-20702 CVE-2025-20701CVE-2025-20701
Target & Sectors
DACH DACH NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/06/22
Threat actors could potentially eavesdrop on Beats Studio Buds users via Bluetooth signals if they exploit the vulnerabilities tracked as CVE-2025-20701, CVE-2025-20700, and CVE-2025-20702.
infrastructure Android
infrastructure Ios
infrastructure 8 iPhone
Tactical Metrics
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
8
Iphone