CVE-2024-27867General(apple / airpods)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple airpods systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airpods
  • airpods_firmware
  • airpods_max
  • airpods_max_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
airpodsairpods_firmwareairpods_maxairpods_max_firmwareairpods_proairpods_pro_firmwarebeats_fit_probeats_fit_pro_firmwarepowerbeatspowerbeats_firmware

1 version affected across 10 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-29: 1Mentions · 2026-05-02: 1Mentions · 2026-05-12: 2Mentions · 2026-05-13: 1Patch / Workaround · 2026-01-29: 1Technical Details · 2026-01-29: 1Technical Details · 2026-05-12: 201-2905-0205-1205-13
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-291
Patch1
2026-05-021
General1
2026-05-122
Disclosure2
2026-05-131
General1
Full discourse5 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-34078 2 - CVE-2026-31431 3 - CVE-2024-27867 4 - CVE-2026-3854 5 - CVE-2026-34263 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five CVEs as trending, without additional context on exploits, patches, or technical details.

    00011175
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2021-3156 3 - CVE-2025-14847 4 - CVE-2024-27867 5 - CVE-2024-11182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVE identifiers as trending with no additional technical, exploit, or mitigation details.

    000111.0K
    1.7K followersView on X
  • Grok@grok
    Patch

    You're right—Bluetooth in earbuds like AirPods has vulnerabilities, like spoofing (CVE-2024-27867) or eavesdropping via missing authentication flaws (e.g., CVE-2025-20700). These could allow decryption or spying if an attacker is nearby, though modern encryption helps. Wired earphones avoid this risk entirely by skipping wireless tech. Updates mitigate issues.

    Post summary

    The note highlights two Bluetooth vulnerabilities (CVE-2024-27867, CVE-2025-20700) in AirPods that enable spoofing or eavesdropping, and it confirms that vendor updates mitigate the risks.

    10000107
    8.1M followersView on X
  • Sprocket@SprocketYT
    Disclosure

    @Mrwhosetheboss June 2024, a significant vulnerability (CVE-2024-27867) was discovered where an attacker in Bluetooth range could spoof a trusted device and connect to someone’s AirPods! 🙄💀

    Post summary

    The tweet announces a newly discovered CVE that permits a Bluetooth spoofing attack on AirPods, but it does not provide a PoC, exploit code, or patch details.

    00000160
    494 followersView on X
  • Sprocket@SprocketYT
    Disclosure

    Security 👀💀 June 2024, a vulnerability (CVE-2024-27867) was discovered where an attacker in Bluetooth range could spoof a trusted device and connect to someone’s AirPods! https://t.co/A2IwyST92k

    Post summary

    The tweet announces the discovery of CVE-2024-27867, detailing a Bluetooth spoofing capability that can connect to AirPods, but offers no PoC, exploit code, or patch information.

    0000066
    494 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
HWappleairpods---
OSappleairpods_firmware---
HWappleairpods_max---
OSappleairpods_max_firmware---
HWappleairpods_pro---
OSappleairpods_pro_firmware---
HWapplebeats_fit_pro---
OSapplebeats_fit_pro_firmware---
HWapplepowerbeats---
OSapplepowerbeats_firmware---

Explore more