Threat reportVulnerabilityTL-2026-0850

Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models

highPATCHED

Airoha Bluetooth SoC Authentication Bypass & RACE Protocol (TL-2026-0850), also tracked as RACE Vulnerabilities, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-06-18. It has no confirmed attribution, affects Apple / Beats Beats Studio Buds, references 3 CVEs (CVE-2025-20700, CVE-2025-20701, CVE-2025-20702), maps to 16 MITRE ATT&CK techniques (T1005, T1011.001, T1068), and is covered by 9 detection rules and 15 indicators of compromise.

CVSS
8.8/10High
CVEs
3Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0850

Threat ID
TL-2026-0850
Also known as
RACE Vulnerabilities, Airoha RACE, Bluetooth Headphone Jacking
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
consumer, government, executive-protection, journalism, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

Malware and tooling: RACE Toolkit

How Airoha Bluetooth SoC Authentication Bypass & RACE Protocol works

A chain of three flaws in Airoha's Bluetooth audio SoC SDK lets an unpaired attacker within radio range read/write device RAM and flash via the proprietary RACE protocol, extract stored Bluetooth link keys, eavesdrop through the microphone via the Hands-Free Profile, and hijack the connection to a paired phone. Apple patched the Beats Studio Buds variant (CVE-2025-20701) in Beats Firmware Update 1B211; the underlying Airoha SDK affects 28+ confirmed earbud/headphone models from Sony, Bose, JBL, Marshall, Jabra and others.

Researchers Dennis Heinze and Frieder Steinmetz of ERNW GmbH discovered that Airoha System-on-Chip (SoC) products used across the consumer Bluetooth audio market expose a powerful proprietary debug/management protocol ERNW dubbed 'RACE' to any device in radio range, with no pairing or authentication required. The protocol is reachable two ways: over Bluetooth Low Energy via a custom GATT service (CVE-2025-20700, Missing Authentication for GATT Services) and over Bluetooth Classic (BR/EDR) via an RFCOMM channel with no pairing enforcement (CVE-2025-20701, Missing Authentication for Bluetooth BR/EDR). RACE itself (CVE-2025-20702) provides critical, unauthenticated primitives: Get Build Version (opcode 0x1E08) for SoC/SDK fingerprinting, Get BD_ADDR (0x0CD5), Read Flash (0x0403), and arbitrary Read/Write RAM (0x1680/0x1681) covering the entire memory map including MMIO registers.

Chaining the three flaws enables a full takeover. An attacker silently connects to a vulnerable headphone, uses RACE to dump flash/RAM, and locates the Bluetooth link key in the connection table within the dumped memory. With the extracted link key and the headphone's BD_ADDR, the attacker can impersonate the headphone to the victim's paired smartphone and abuse the Bluetooth Hands-Free Profile (HFP) to issue AT commands: initiate calls to arbitrary numbers, retrieve call history and contacts, and trigger the voice assistant. Eavesdropping is demonstrated by triggering a call to an attacker-controlled number; once the audio link is established the attacker listens through the device microphone. Because exploitation requires no user interaction and no pairing, any of the ~28 confirmed devices within ~10 meters is a potential target. The three CVEs each carry CVSS 3.1 base score 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and map to CWE-306 (Missing Authentication for Critical Function).

The root cause is shared Airoha SDK code reused by many vendors; affected components are the Airoha IoT SDK for BT audio v5.5.0 and earlier and the Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier. ERNW reported to Airoha on 2025-03-25, received a response on 2025-05-27, and Airoha distributed a fixed SDK to manufacturers on 2025-06-04, shortly before partial public disclosure around TROOPERS 2025 (2025-06-26). Full technical disclosure including the RACE Toolkit proof-of-concept followed in December 2025. Apple shipped the Beats Studio Buds fix as Beats Firmware Update 1B211, auto-delivered when the buds pair with an iPhone, iPad or Mac. While exploitation is realistic, ERNW assessed practical attacks as requiring technical sophistication and likely limited to high-value targets.

MITRE ATT&CK techniques used in TL-2026-0850

Collection

T1005 Data from Local System; T1123 Audio Capture; T1557 Adversary-in-the-Middle

Exfiltration

T1011.001 Exfiltration Over Bluetooth

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Discovery

T1082 System Information Discovery; T1120 Peripheral Device Discovery

Command and Control

T1095 Non-Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Credential Access

T1212 Exploitation for Credential Access; T1552.001 Credentials In Files

Persistence

T1542.001 System Firmware

Impact

T1565.001 Stored Data Manipulation

Reconnaissance

T1592 Gather Victim Host Information

stealth

T1684.001 Impersonation

Affected products and versions in Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

  • Apple / Beats — Beats Studio Buds
    Vulnerable versions: firmware prior to 1B211
    Fixed in: 1B211
  • Airoha — IoT SDK for BT audio
    Vulnerable versions: v5.5.0 and earlier
    Fixed in: post-v5.5.0 SDK
  • Airoha — AB1561x/AB1562x/AB1563x SDK
    Vulnerable versions: v3.3.1 and earlier
    Fixed in: post-v3.3.1 SDK
  • Sony — WH-1000XM4 / WH-1000XM5 / WH-1000XM6 / WF-1000XM3 / WF-1000XM4 / WF-1000XM5 / CH-720N / Link Buds S / ULT Wear / WF-C500 / WF-C510-GFP / WH-CH520 / WH-XB910N / WI-C100
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK
  • Bose — QuietComfort Earbuds
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK
  • JBL — Endurance Race 2 / Live Buds 3
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK
  • Marshall — ACTON III / MAJOR V / MINOR IV / MOTIF II / STANMORE III / WOBURN III
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK
  • Jabra — Elite 8 Active
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK
  • Beyerdynamic — Amiron 300
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK
  • Jlab — Epic Air Sport ANC
    Vulnerable versions: pre-fixed-SDK firmware
    Fixed in: vendor firmware with Airoha fixed SDK

Remediation for Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

Patches

  • Beats Firmware Update 1B211 (Beats Studio Buds)
  • Airoha IoT SDK for BT audio fixed release (post-v5.5.0)
  • Airoha AB1561x/AB1562x/AB1563x SDK fixed release (post-v3.3.1)

Immediate actions

  • Apply Beats Firmware Update 1B211 by pairing Beats Studio Buds with an up-to-date iPhone, iPad or Mac so the firmware auto-installs
  • For non-Beats devices, install the latest vendor firmware that incorporates the Airoha fixed SDK (distributed to manufacturers 2025-06-04)
  • Power off or disable Bluetooth on vulnerable headphones in high-risk/sensitive environments until patched
  • Treat any unpatched Airoha-based headphone as an untrusted microphone near confidential conversations

Workarounds

  • Disable Bluetooth on the headphones when not in active use
  • Avoid using affected headphones during sensitive meetings until firmware is confirmed patched

Longer-term hardening

  • Inventory Bluetooth audio devices and track which use Airoha SoCs (AB1561x/AB1562x/AB1563x)
  • Adopt a vendor firmware update SLA and verify devices auto-update when paired
  • Prefer audio devices whose vendors publish a coordinated vulnerability disclosure and firmware update track record

CVEs associated with Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

CVE-2025-20700, CVE-2025-20701, CVE-2025-20702

Weaknesses (CWE) in Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

CWE-306

Timeline of Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

  • ERNW (Dennis Heinze, Frieder Steinmetz) privately reported the Airoha Bluetooth SoC vulnerabilities to Airoha
  • Airoha responded to ERNW's disclosure after roughly two months
  • Airoha distributed a fixed Bluetooth audio SDK to device manufacturers
  • ERNW published partial public disclosure (Insinuator advisory) around TROOPERS 2025, listing ~28 confirmed affected devices
  • Security press (Dark Reading and others) expanded coverage detailing risk to Sony, Bose, JBL, Marshall and Jabra earbuds/headphones built on the affected Airoha SoC SDK
  • CVE-2025-20700/20701/20702 published in NVD, each rated CVSS 3.1 8.8 (CWE-306)
  • ERNW released full technical disclosure of the RACE protocol and the RACE Toolkit proof-of-concept on GitHub
  • Apple shipped Beats Firmware Update 1B211 fixing the Beats Studio Buds variant (CVE-2025-20701); reported by BleepingComputer

Sources cited for Airoha Bluetooth SoC Authentication Bypass & RACE Protocol

Detection coverage for TL-2026-0850

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0850 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats