Threat reportVulnerabilityTL-2026-0850
Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models
Airoha Bluetooth SoC Authentication Bypass & RACE Protocol (TL-2026-0850), also tracked as RACE Vulnerabilities, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-06-18. It has no confirmed attribution, affects Apple / Beats Beats Studio Buds, references 3 CVEs (CVE-2025-20700, CVE-2025-20701, CVE-2025-20702), maps to 16 MITRE ATT&CK techniques (T1005, T1011.001, T1068), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0850
- Threat ID
- TL-2026-0850
- Also known as
- RACE Vulnerabilities, Airoha RACE, Bluetooth Headphone Jacking
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- consumer, government, executive-protection, journalism, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
Malware and tooling: RACE Toolkit
How Airoha Bluetooth SoC Authentication Bypass & RACE Protocol works
A chain of three flaws in Airoha's Bluetooth audio SoC SDK lets an unpaired attacker within radio range read/write device RAM and flash via the proprietary RACE protocol, extract stored Bluetooth link keys, eavesdrop through the microphone via the Hands-Free Profile, and hijack the connection to a paired phone. Apple patched the Beats Studio Buds variant (CVE-2025-20701) in Beats Firmware Update 1B211; the underlying Airoha SDK affects 28+ confirmed earbud/headphone models from Sony, Bose, JBL, Marshall, Jabra and others.
Researchers Dennis Heinze and Frieder Steinmetz of ERNW GmbH discovered that Airoha System-on-Chip (SoC) products used across the consumer Bluetooth audio market expose a powerful proprietary debug/management protocol ERNW dubbed 'RACE' to any device in radio range, with no pairing or authentication required. The protocol is reachable two ways: over Bluetooth Low Energy via a custom GATT service (CVE-2025-20700, Missing Authentication for GATT Services) and over Bluetooth Classic (BR/EDR) via an RFCOMM channel with no pairing enforcement (CVE-2025-20701, Missing Authentication for Bluetooth BR/EDR). RACE itself (CVE-2025-20702) provides critical, unauthenticated primitives: Get Build Version (opcode 0x1E08) for SoC/SDK fingerprinting, Get BD_ADDR (0x0CD5), Read Flash (0x0403), and arbitrary Read/Write RAM (0x1680/0x1681) covering the entire memory map including MMIO registers.
Chaining the three flaws enables a full takeover. An attacker silently connects to a vulnerable headphone, uses RACE to dump flash/RAM, and locates the Bluetooth link key in the connection table within the dumped memory. With the extracted link key and the headphone's BD_ADDR, the attacker can impersonate the headphone to the victim's paired smartphone and abuse the Bluetooth Hands-Free Profile (HFP) to issue AT commands: initiate calls to arbitrary numbers, retrieve call history and contacts, and trigger the voice assistant. Eavesdropping is demonstrated by triggering a call to an attacker-controlled number; once the audio link is established the attacker listens through the device microphone. Because exploitation requires no user interaction and no pairing, any of the ~28 confirmed devices within ~10 meters is a potential target. The three CVEs each carry CVSS 3.1 base score 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and map to CWE-306 (Missing Authentication for Critical Function).
The root cause is shared Airoha SDK code reused by many vendors; affected components are the Airoha IoT SDK for BT audio v5.5.0 and earlier and the Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier. ERNW reported to Airoha on 2025-03-25, received a response on 2025-05-27, and Airoha distributed a fixed SDK to manufacturers on 2025-06-04, shortly before partial public disclosure around TROOPERS 2025 (2025-06-26). Full technical disclosure including the RACE Toolkit proof-of-concept followed in December 2025. Apple shipped the Beats Studio Buds fix as Beats Firmware Update 1B211, auto-delivered when the buds pair with an iPhone, iPad or Mac. While exploitation is realistic, ERNW assessed practical attacks as requiring technical sophistication and likely limited to high-value targets.
MITRE ATT&CK techniques used in TL-2026-0850
Collection
T1005 Data from Local System; T1123 Audio Capture; T1557 Adversary-in-the-Middle
Exfiltration
T1011.001 Exfiltration Over Bluetooth
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Discovery
T1082 System Information Discovery; T1120 Peripheral Device Discovery
Command and Control
T1095 Non-Application Layer Protocol
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Credential Access
T1212 Exploitation for Credential Access; T1552.001 Credentials In Files
Persistence
Impact
T1565.001 Stored Data Manipulation
Reconnaissance
T1592 Gather Victim Host Information
stealth
Affected products and versions in Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
- Apple / Beats — Beats Studio Buds
Vulnerable versions: firmware prior to 1B211
Fixed in: 1B211 - Airoha — IoT SDK for BT audio
Vulnerable versions: v5.5.0 and earlier
Fixed in: post-v5.5.0 SDK - Airoha — AB1561x/AB1562x/AB1563x SDK
Vulnerable versions: v3.3.1 and earlier
Fixed in: post-v3.3.1 SDK - Sony — WH-1000XM4 / WH-1000XM5 / WH-1000XM6 / WF-1000XM3 / WF-1000XM4 / WF-1000XM5 / CH-720N / Link Buds S / ULT Wear / WF-C500 / WF-C510-GFP / WH-CH520 / WH-XB910N / WI-C100
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK - Bose — QuietComfort Earbuds
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK - JBL — Endurance Race 2 / Live Buds 3
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK - Marshall — ACTON III / MAJOR V / MINOR IV / MOTIF II / STANMORE III / WOBURN III
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK - Jabra — Elite 8 Active
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK - Beyerdynamic — Amiron 300
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK - Jlab — Epic Air Sport ANC
Vulnerable versions: pre-fixed-SDK firmware
Fixed in: vendor firmware with Airoha fixed SDK
Remediation for Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
Patches
- Beats Firmware Update 1B211 (Beats Studio Buds)
- Airoha IoT SDK for BT audio fixed release (post-v5.5.0)
- Airoha AB1561x/AB1562x/AB1563x SDK fixed release (post-v3.3.1)
Immediate actions
- Apply Beats Firmware Update 1B211 by pairing Beats Studio Buds with an up-to-date iPhone, iPad or Mac so the firmware auto-installs
- For non-Beats devices, install the latest vendor firmware that incorporates the Airoha fixed SDK (distributed to manufacturers 2025-06-04)
- Power off or disable Bluetooth on vulnerable headphones in high-risk/sensitive environments until patched
- Treat any unpatched Airoha-based headphone as an untrusted microphone near confidential conversations
Workarounds
- Disable Bluetooth on the headphones when not in active use
- Avoid using affected headphones during sensitive meetings until firmware is confirmed patched
Longer-term hardening
- Inventory Bluetooth audio devices and track which use Airoha SoCs (AB1561x/AB1562x/AB1563x)
- Adopt a vendor firmware update SLA and verify devices auto-update when paired
- Prefer audio devices whose vendors publish a coordinated vulnerability disclosure and firmware update track record
CVEs associated with Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
Weaknesses (CWE) in Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
Timeline of Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
- ERNW (Dennis Heinze, Frieder Steinmetz) privately reported the Airoha Bluetooth SoC vulnerabilities to Airoha
- Airoha responded to ERNW's disclosure after roughly two months
- Airoha distributed a fixed Bluetooth audio SDK to device manufacturers
- ERNW published partial public disclosure (Insinuator advisory) around TROOPERS 2025, listing ~28 confirmed affected devices
- Security press (Dark Reading and others) expanded coverage detailing risk to Sony, Bose, JBL, Marshall and Jabra earbuds/headphones built on the affected Airoha SoC SDK
- CVE-2025-20700/20701/20702 published in NVD, each rated CVSS 3.1 8.8 (CWE-306)
- ERNW released full technical disclosure of the RACE protocol and the RACE Toolkit proof-of-concept on GitHub
- Apple shipped Beats Firmware Update 1B211 fixing the Beats Studio Buds variant (CVE-2025-20701); reported by BleepingComputer
Sources cited for Airoha Bluetooth SoC Authentication Bypass & RACE Protocol
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
- Security Advisory: Airoha-based Bluetooth Headphones and Earbuds
- Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities
- RACE Toolkit (proof-of-concept exploitation tool)
- Airoha Chip Vulns Put Sony, Bose Earbuds & Headphones at Risk
- Bluetooth flaws could let hackers spy through your microphone
- NVD - CVE-2025-20702
- Tenable - CVE-2025-20701
- Tenable - CVE-2025-20700
- Airoha Product Security Bulletin 2025
Detection coverage for TL-2026-0850
As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0850 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.