CVE-2025-20701Patch

HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

7.8/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 12 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 19 signals
  • Disclosure: 3 classified signals
  • Peaked 10d ago at 7 mentions (2026-06-19); latest day: 1
  • 23 total mentions across 12 days

Deep dive

Activity timeline23 mentions / 12d
02457Mentions · 2026-06-18: 2Mentions · 2026-06-19: 7Mentions · 2026-06-20: 1Mentions · 2026-06-21: 1Mentions · 2026-06-22: 2Mentions · 2026-07-01: 1Mentions · 2026-07-05: 1Mentions · 2026-09-08: 1Mentions · 2026-09-10: 4Mentions · 2026-09-11: 1Mentions · 2026-09-13: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-09-10: 1Exploit Tool / Code · 2026-06-21: 1Exploit Tool / Code · 2026-09-08: 1Active Exploitation · 2026-06-19: 2Active Exploitation · 2026-09-10: 1Patch / Workaround · 2026-06-18: 2Patch / Workaround · 2026-06-19: 5Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 2Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-10: 2Patch / Workaround · 2026-09-11: 1Patch / Workaround · 2026-09-13: 1Technical Details · 2026-06-18: 2Technical Details · 2026-06-19: 7Technical Details · 2026-06-20: 1Technical Details · 2026-06-21: 1Technical Details · 2026-06-22: 2Technical Details · 2026-07-05: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-10: 2Technical Details · 2026-09-11: 1Technical Details · 2026-09-13: 106-1806-1906-2006-2106-2207-0107-0509-0809-1009-1109-1309-15
Signal classification5 categories
Patch
1463.6%
Active Exploitation
313.6%
Disclosure
313.6%
General
14.5%
Exploit
14.5%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-06-182
Patch2
2026-06-197
Active Exploitation2Patch5
2026-06-201
Patch1
2026-06-211
Patch1
2026-06-222
Patch2
2026-07-011
General1
2026-07-051
Disclosure1
2026-09-081
Exploit1
2026-09-104
Active Exploitation1Disclosure1Patch2
2026-09-111
Patch1
2026-09-131
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ Apple fixed a Beats Studio Buds bug (CVE-2025-20701) that could let a nearby attacker listen through the microphone when the device was not yet paired and seeking pair requests. Update to firmware 1B211. Read the full story: https://thehackernews.com/2026/06/apple-patches-beats-studio-buds-flaw.html

    Post summary

    Apple released firmware 1B211 to patch CVE‑2025‑20701, a proximity microphone flaw in Beats Studio Buds that could let an unpaired attacker eavesdrop on a nearby device.

    120574939.3K
    2.2M followersView on X
  • RIFFSEC@getriffsec
    Patch

    🎧 Beats z podsłuchem Apple załatało krytyczną lukę w Beats Studio Buds, która mogła pozwalać na podsłuch przez Bluetooth. Problem dostał oznaczenie CVE-2025-20701 i dotyczył procesu parowania słuchawek. W uproszczeniu: atakujący znajdujący się blisko urządzenia mógł wykorzystać błąd w uwierzytelnianiu i uzyskać dostęp do mikrofonu słuchawek, zanim zostały poprawnie sparowane. Nie jest to scenariusz masowy ani zdalny „z drugiego końca świata”, ale sam typ podatności jest ciekawy. Apple wypuściło poprawkę w firmware 1B211. Aktualizacja powinna instalować się automatycznie, gdy słuchawki są w etui, mają baterię i znajdują się blisko sparowanego iPhone’a, iPada albo Maca. Źródło: Cyber Security Hub

    Post summary

    Apple patched CVE‑2025‑20701 in Beats Studio Buds with firmware 1B211, fixing a local Bluetooth authentication flaw that could allow attackers to access the earbuds’ microphone during pairing.

    10020652
    3.0K followersView on X
  • TechNadu@TechNadu
    Patch

    🛡️ @skullcandy Dime 3 earbuds can accept Bluetooth connections from nearby unpaired devices without owner approval. CVE-2025-20701 could enable audio hijacking and even live microphone access. A patched firmware exists. The problem? Consumers currently can’t install it. https://t.co/dIjNiQu5wa

    Post summary

    The tweet announces a Bluetooth flaw in Skullcandy Dime 3 earbuds, noting that a firmware patch exists but consumers cannot easily apply it.

    10010168
    10.0K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    Apple patches Beats Studio Buds vulnerability (CVE-2025-20701) that allows nearby hackers to eavesdrop. Also: new iPhone BootROM exploit discovered. https://www.redsecuretech.co.uk/blog/post/beats-studio-buds-bluetooth-flaw-allows-eavesdropping/1254 #BeatsStudioBuds #CVE #BluetoothVulnerability #Eavesdropping #Airoha #iPhone #BootROM #AppleSecurity https://t.co/pXhmiGcJZ7

    Post summary

    Apple has issued a patch for CVE‑2025‑20701, which sprayed Beats Studio Buds with a Bluetooth eavesdropping flaw, while a new iPhone BootROM exploit is also highlighted.

    0101056
    66 followersView on X
  • Total Cyber-Sec@totalcybersec
    Disclosure

    1/3 🎧 CVE-2025-20701 afecta #SkullcandyDime3 con firmware 1.0.0.28. Un atacante dentro del alcance #Bluetooth puede emparejar su dispositivo sin tocar los audífonos, introducir un PIN o recibir aprobación del propietario. #IoTSecurity

    Post summary

    The tweet discloses a Bluetooth pairing flaw (CVE-2025-20701) that affects Skullcandy Dime3 firmware 1.0.0.28, enabling unauthorized pairing without physical contact.

    1000044
    15.8K followersView on X
  • Glitch News@glitch4techs
    Patch

    ثغرة تجسس خطيرة تهدد خصوصية مستخدمي Beats Buds! هل أنت آمن؟ آبل تُجبر على سد فجوة أمنية عالية الخطورة بسماعاتها اللاسلكية 🛡 أصدرت آبل تحديثاً عاجلاً لسماعات Beats Studio Buds لمعالجة ثغرة CVE-2025-20701، المصنفة بخطورة 8.8 (CVSS)، والتي كانت تسمح لمهاجمين ضمن نطاق Bluetooth بالتنصت على المستخدمين عبر الميكروفون دون علمهم. يأتي هذا الإجراء الضروري بعد اكتشاف الثغرة من قبل باحثي ERNW GmbH، ويؤكد على المخاطر الكامنة في أجهزة الاستماع المتصلة. بالموازاة، تم الكشف عن استغلال usbliter8 الجديد لشرائح A12 وA13 من آبل، والذي يعتبر 'غير قابل للترقيع' ويستغل عيوباً في متحكم USB لفتح أبواب خلفية دائمة. 🔹 CVE-2025-20701: ثغرة في Airoha Bluetooth audio SDK تسمح بالاقتران غير المصرح به ووصول الميكروفون. ⚡ تحديث 1B211: آبل عالجت الخلل في Beats Studio Buds، داعية المستخدمين لتحديث أجهزتهم فوراً لضمان الحماية. 🔐 usbliter8: استغلال خطير يستهدف BootROM في A12/A13، يستفيد من عيوب عتادية ولا يمكن إصلاحه عبر تحديثات البرمجيات. 🧠 المخاطر المترتبة: تنوع التهديدات من التنصت السمعي إلى اختراق أساسيات أمان الجهاز، مما يطرح تحديات جسيمة. هذه التطورات تضع خصوصية المستخدمين وأمان أجهزتهم على المحك، وتبرز ضرورة اليقظة المستمرة من الشركات والمستخدمين على حد سواء. الاستغلال غير القابل للترقيع يعني أن بعض الأجهزة القديمة ستبقى عرضة للخطر بشكل دائم، مما قد يدفع نحو تغيير العتاد. هل تقع مسؤولية الأمان على الشركة المصنعة أم على المستخدم النهائي في عالم يتطور فيه التهديد باستمرار؟ شاركونا آراءكم 👇 #Glitch4Techs #Apple #IPhone 🔗 اقرأ المقال كاملاً:

    Post summary

    Apple announced a critical patch for Beats Buds to address CVE‑2025‑20701, a high‑severity Bluetooth sniffing flaw, while also highlighting the non‑patchable usbliter8 exploit targeting older A12/A13 devices.

    10000220
    24 followersView on X
  • protect_cyber_sec@AmirHossein_sec

    برای ایرپاد مدل Skullcandy Dime 3 ، آسیب پذیری با کد شناسایی CVE-2025-20701 برای Bluetooth این نوع دیوایس ها منتشر شده است. این آسیب پذیری باعث hijack شدن session برقرار شده این مدل دیوایس با گوشی همراه کاربر می شود و هکرها می توانند صدا و وویس های کاربر را کپچر و sniff نمایند. https://t.co/lCz1LFmGD6

    0000056
    207 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Skullcandy Dime 3 kulaklıklarda kritik Bluetooth açığı! Skullcandy Dime 3'ün 1.0.0.28 firmware sürümündeki güvenlik açığı, Bluetooth menzilindeki saldırganların kullanıcı onayı olmadan kulaklıkla eşleşmesine ve bağlantıyı ele geçirmesine neden olabiliyor. 🔴 CVE-2025-20701 | VU#859658 Saldırgan; 🔹 Pairing modunun açılmasına gerek olmadan eşleşebiliyor, 🔹 A2DP üzerinden ses akışını ele geçirebiliyor, 🔹 HFP/HSP üzerinden kulaklığın mikrofonuna erişerek çevredeki sesleri dinleyebiliyor. Üstelik saldırgan bir kez eşleştirildiğinde güvenilir Bluetooth cihazı haline geliyor ve tekrar menzile girdiğinde otomatik bağlanabiliyor. ⚠️ Daha da dikkat çekici olanı: Kullanıcı yalnızca New device paired uyarısını duyuyor; bağlantıyı önceden reddetme imkanı bulunmuyor. 🩹 Bu açığın 1.0.0.30 sürümünde düzeltildiği bildiriliyor. Ancak Dime 3'ün Skullcandy uygulaması üzerinden firmware güncellemesini desteklememesi nedeniyle mevcut 1.0.0.28 kullanıcıları için güncelleme konusu ayrıca problem.

    Post summary

    A new critical Bluetooth vulnerability (CVE‑2025‑20701) in Skullcandy Dime 3 enables attackers to pair without user consent, hijack audio, and record mic activity. Firmware 1.0.0.30 fixes the flaw, but affected users may need manual updating.

    00000212
    2.3K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical flaw discovered in Skullcandy Dime 3 earbuds running firmware 1.0.0.28: attackers nearby can auto-pair without consent, hijack audio via A2DP and access the mic—thanks to a weakness in the Airoha Bluetooth audio SDK (CVE-2025-20701). Patch 1.0.0.30 fixes it, but there’s no way to install via the app. Users should monitor for “new device paired”, remove unknown Bluetooth devices, and avoid using these earbuds where strangers are close. #Bluetooth #Security #Skullcandy #Vulnerability #CVE #AudioHijack #Bluetooth #Security #Skullcandy #Vulnerability #AudioHijack #CVE https://thedailytechfeed.com/major-bluetooth-flaw-in-skullcandy-dime-3-lets-attackers-hijack-audio-spy-via-mic/

    Post summary

    The tweet highlights a critical flaw in Skullcandy Dime 3 earbuds, provides patch details (firmware 1.0.0.30), and recommends defensive measures to mitigate potential exploitation.

    0000064
    723 followersView on X
  • TechNadu@TechNadu
    Patch

    CERT/CC says affected Dime 3 owners have no known consumer-accessible path from firmware 1.0.0.28 to the patched 1.0.0.30: https://www.technadu.com/skullcandy-dime-3-earbuds-vulnerable-to-silent-bluetooth-hijacking-cve-2025-20701/636417/

    Post summary

    CERT/CC reports that consumers cannot exploit the vulnerability via firmware 1.0.0.28 and highlights the availability of the patched firmware 1.0.0.30.

    0000087
    10.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-20701 to hijack Skullcandy Dime 3 earbuds without user interaction. Once paired, they capture microphone audio and maintain persistent access through automatic reconnection. The vulnerability affects millions of devices with limited update paths. #Vulnerability #IoTSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/skullcandy-dime-3-bluetooth-hijacking-cve-2025-20701

    Post summary

    The post reports that attackers are actively exploiting CVE-2025-20701 to hijack Skullcandy Dime 3 earbuds, capturing audio and maintaining persistence, with no mention of patches or mitigations.

    0000067
    2.0K followersView on X
  • OJOBIT@0J0BIT
    Exploit

    An attacker can use it to capture live microphone audio. A nearby attacker can pair with Dime 3 earbuds at firmware 1.0.0.28, hijack audio, and activate the mic-CVE-2025-20701 has a patch, but no consumer update path. CERT/CC advisory VU#859658 says Skullcandy Dime 3 earbuds running firmware 1.0.0.28 accept Bluetooth Classic pairing from any nearby unpaired device without user interaction, letting an attacker interrupt audio and... The vendor considers firmware 1.0.0.30 fixed, but Skullcandy offers no consumer-accessible way to update existing units. Any nearby attacker can push a Bluetooth Classic pairing request at Skullcandy Dime 3 earbuds running firmware 1.0.0.28 and get a completed bond without touching the case, pressing a button, or knowing a PIN. Underlying issue is CVE-2025-20701, described in the Airoha Bluetooth audio SDK as a possible way to pair a Bluetooth audio device without user consent. https://news.ojobit.com/story/skullcandy-dime-3-bluetooth-pairing-vulnerability-3ae449

    Post summary

    The post outlines how CVE-2025-20701 allows nearby attackers to hijack audio on Skullcandy Dime 3 earbuds via unauthorized Bluetooth pairing and notes that a patch exists in firmware 1.0.0.30, but no active exploitation or PoC code is referenced.

    0000023
    15 followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    Beats Studio Buds sizi dinleyebilir: Bluetooth menzilinde kimlik doğrulaması yok! ERNW güvenlik firması, Beats Studio Buds'ın Airoha SoC çipindeki Bluetooth BR/EDR açığını (CVE-2025-20701) keşfetti. Eşleştirme modundaki kulaklık, saldırgana mikrofon erişimi ve çevre ses dinleme imkânı veriyor. • Kimlik doğrulaması gerektirmiyor — Bluetooth menzininde olmak yeterli. • Arama geçmişi ve rehbere erişim, HFP üzerinden komut gönderme ve aktif aramaların dinlenmesi mümkün. • Yama: Beats Firmware 1B211 — iPhone, iPad veya Mac yakınındayken otomatik yükleniyor. Kulaklığınızın güncellendiğini doğrulayın; özellikle hassas ortamlarda Beats takıyorsanız! #SiberGüvenlik #Apple #Bluetooth

    Post summary

    The post announces the discovery of a Bluetooth authentication flaw (CVE-2025-20701) in Beats Studio Buds that allows remote microphone access, and notes that a firmware patch is available.

    0000075
    36 followersView on X
  • 未熟者@myhackinglabo
    General

    Bluetooth イヤホンが盗聴器化 — Beats Studio Buds の CVE-2025-20701 が暴いた Airoha SDK 汚染 https://hackinglabo.com/article/beats-studio-buds-airoha-cve-2025-20701?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet merely names a CVE related to Beats Studio Buds, hints at SDK contamination, and provides a link to a news article, offering no concrete technical or exploit details.

    0000086
    72 followersView on X
  • ohmohm@ohmohm
    Patch

    แอปเปิลอัปเดต Beats Studio Buds แก้ช่องโหว่ CVE-2025-20701 แอบฟังผ่านไมโครโฟน https://monsterconnect.co.th/apple-patches-beats-studio-buds-flaw

    Post summary

    Apple released an update for Beats Studio Buds to patch CVE‑2025‑20701, which would otherwise enable eavesdropping through the microphone.

    0000094
    3.7K followersView on X
  • 高安 カルロス@Kazeshini_
    Patch

    Apple corrige falha grave nos Beats Studio Buds que permitia espionagem de conversas: a vulnerabilidade CVE-2025-20701 dava a um invasor dentro do alcance do Bluetooth a capacidade de ouvir pelo microfone de um dispositivo ainda não pareado enquanto ele buscava solicitações de conexão. O problema foi corrigido com o firmware 1B211, distribuído automaticamente aos fones quando estiverem pareados e próximos de um iPhone, iPad ou Mac. As informações são do site BleepingComputer.

    Post summary

    Apple has deployed firmware 1B211 to patch CVE‑2025‑20701 in Beats Studio Buds, fixing a Bluetooth‑based microphone espionage flaw.

    0000055
    360 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2025-20701 to pair with Beats Studio Buds without user consent, gaining unauthorized microphone access. The vulnerability in Airoha's Bluetooth SDK enabled attackers within range to escalate privileges and potentially pivot to connected devices. #BluetoothSecurity #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/apple-patches-beats-studio-buds-flaw-cve-2025-20701

    Post summary

    CVE‑2025‑20701 is actively exploited to pair with Beats Studio Buds and gain unauthorized microphone access, as shown by TRC analysis.

    0000042
    1.9K followersView on X
  • BreachBriefs@BreachBrief
    Patch

    📢Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio device without user consent. Successful exploitation of the flaw could lead to remote escalation of privilege without requiring any additional execution privileges or user interaction. #CyberSecurity #Apple #CVE #Vulnerability

    Post summary

    Apple patched CVE-2025-20701 affecting Beats Studio Buds, which allowed unauthorized pairing and potential privilege escalation.

    0000038
    8 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Apple's latest firmware update for Beats Studio Buds addresses a critical Bluetooth vulnerability (CVE-2025-20701) that allowed nearby attackers to eavesdrop via the device's microphone. Users should update to Firmware 1B211 to secure their devices. #Apple #BeatsStudioBuds #Security #Bluetooth #FirmwareUpdate #CVE202520701 https://thedailytechfeed.com/apple-fixes-beats-studio-buds-vulnerability-allowing-nearby-eavesdropping/

    Post summary

    Apple released a firmware update (Firmware 1B211) for Beats Studio Buds to fix CVE‑2025‑20701, a Bluetooth eavesdropping vulnerability.

    0000039
    411 followersView on X
  • CyberX@CyberXlx9q
    Patch

    ‼️Apple has patched a high-severity vulnerability in Beats Studio Buds that could have allowed attackers within Bluetooth range to secretly eavesdrop through the earbuds’ microphone. Tracked as CVE-2025-20701, the flaw affected devices actively seeking pairing requests. Security researchers found that nearby attackers could potentially exploit the weakness without prior pairing. Apple addressed the issue in Beats Firmware Update 1B211, which is being delivered automatically to affected devices. If you use Beats Studio Buds, make sure your firmware is up to date. https://arstechnica.com/apple/2026/06/apple-patches-high-severity-eavesdropping-vulnerability-in-beats-studio-buds/ #Apple #BeatsStudioBuds #CyberSecurity #BluetoothSecurity #Vulnerability #Privacy #InfoSec

    Post summary

    Apple has released an automatic firmware update for Beats Studio Buds to mitigate a high‑severity eavesdropping vulnerability that allowed attackers within Bluetooth range to listen via the earbuds' microphone.

    00000107
    217 followersView on X

Explore more