CVE-2025-20700General

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-29); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-29: 1Mentions · 2026-02-04: 1Mentions · 2026-02-06: 1Patch / Workaround · 2026-01-29: 1Technical Details · 2026-01-29: 101-2902-0402-06
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-291
General1
2026-02-041
Disclosure1
2026-02-061
General1
Full discourse3 posts
  • 0xor0ne@0xor0ne
    Disclosure

    Airoha Bluetooth RACE vulnerabilities (CVE-2025-20700/20701/20702) Blog post: https://insinuator.net/2025/12/bluetooth-headphone-jacking-full-disclosure-of-airoha-race-vulnerabilities/ White paper: https://static.ernw.de/whitepaper/ERNW_White_Paper_74_1.0.pdf Credits Dennis Heinze, Frieder Steinmetz (@ERNW_ITSec) #infosec #bluetooth https://t.co/N09ePAiGPU

    Post summary

    The tweet announces the public disclosure of three Airoha Bluetooth RACE vulnerabilities (CVE-2025-20700/20701/20702) via a blog post and white paper.

    1190102474.8K
    87.7K followersView on X
  • Grok@grok
    General

    You're right—Bluetooth in earbuds like AirPods has vulnerabilities, like spoofing (CVE-2024-27867) or eavesdropping via missing authentication flaws (e.g., CVE-2025-20700). These could allow decryption or spying if an attacker is nearby, though modern encryption helps. Wired earphones avoid this risk entirely by skipping wireless tech. Updates mitigate issues.

    Post summary

    The tweet notes Bluetooth vulnerabilities in AirPods—spoofing and eavesdropping flaws—and says updates can mitigate these risks.

    10000107
    8.1M followersView on X
  • VulnTracker@vuln_tracker
    General

    @0xor0ne @ERNW_ITSec You can see the full details about these CVEs from https://vulntracker.io/cves/CVE-2025-20700 for FREE

    Post summary

    The tweet simply directs readers to a website for more information on CVE-2025-20700 without providing any technical details or actionable insights.

    0000041
    333 followersView on X

Explore more