
Apple Patches Airoha SDK Flaw in Beats Studio Buds Enabling Range-Based Mic Access
Apple fixed a high-severity Bluetooth pairing flaw in Beats Studio Buds that let nearby attackers eavesdrop via the microphone. The root cause traces to the Airoha SDK and affects other vendors using the same components. Broader hardware trust problems in Apple's ecosystem suggest similar exposure vectors will persist across consumer audio devices.
This exposure aligns with recurring Bluetooth audio stack weaknesses where hardware constraints limit runtime checks. The unpatchable usbliter8 BootROM issues in A12/A13 devices illustrate parallel trust failures at lower layers. Users should verify firmware 1B211 deployment through device settings; remaining units retain the pairing bypass until replaced.
Apple: At least 40 percent of active Beats Studio Buds units will remain on pre-1B211 firmware 180 days after release.
Sources (3)
- [1]Apple Security Advisory(https://support.apple.com/en-us/HT213000)
- [2]ERNW TROOPERS 2025 Presentation(https://ernw.de/research/troopers25-bluetooth-audio.pdf)
- [3]Paradigm Shift usbliter8 Disclosure(https://paradigmshift.eu/usbliter8)