# Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models

> A chain of three flaws in Airoha's Bluetooth audio SoC SDK lets an unpaired attacker within radio range read/write device RAM and flash via the proprietary RACE protocol, extract stored Bluetooth link keys, eavesdrop through the microphone via the Hands-Free Profile, and hijack the connection to a paired phone. Apple patched the Beats Studio Buds variant (CVE-2025-20701) in Beats Firmware Update 1B211; the underlying Airoha SDK affects 28+ confirmed earbud/headphone models from Sony, Bose, JBL, Marshall, Jabra and others.

- **Published:** 2026-06-18T00:00:00Z
- **Last reviewed:** 2026-06-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0850
- **ID:** TL-2026-0850
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-20700, CVE-2025-20701, CVE-2025-20702

## Description

Researchers Dennis Heinze and Frieder Steinmetz of ERNW GmbH discovered that Airoha System-on-Chip (SoC) products used across the consumer Bluetooth audio market expose a powerful proprietary debug/management protocol ERNW dubbed 'RACE' to any device in radio range, with no pairing or authentication required. The protocol is reachable two ways: over Bluetooth Low Energy via a custom GATT service (CVE-2025-20700, Missing Authentication for GATT Services) and over Bluetooth Classic (BR/EDR) via an RFCOMM channel with no pairing enforcement (CVE-2025-20701, Missing Authentication for Bluetooth BR/EDR). RACE itself (CVE-2025-20702) provides critical, unauthenticated primitives: Get Build Version (opcode 0x1E08) for SoC/SDK fingerprinting, Get BD_ADDR (0x0CD5), Read Flash (0x0403), and arbitrary Read/Write RAM (0x1680/0x1681) covering the entire memory map including MMIO registers.

Chaining the three flaws enables a full takeover. An attacker silently connects to a vulnerable headphone, uses RACE to dump flash/RAM, and locates the Bluetooth link key in the connection table within the dumped memory. With the extracted link key and the headphone's BD_ADDR, the attacker can impersonate the headphone to the victim's paired smartphone and abuse the Bluetooth Hands-Free Profile (HFP) to issue AT commands: initiate calls to arbitrary numbers, retrieve call history and contacts, and trigger the voice assistant. Eavesdropping is demonstrated by triggering a call to an attacker-controlled number; once the audio link is established the attacker listens through the device microphone. Because exploitation requires no user interaction and no pairing, any of the ~28 confirmed devices within ~10 meters is a potential target. The three CVEs each carry CVSS 3.1 base score 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and map to CWE-306 (Missing Authentication for Critical Function).

The root cause is shared Airoha SDK code reused by many vendors; affected components are the Airoha IoT SDK for BT audio v5.5.0 and earlier and the Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier. ERNW reported to Airoha on 2025-03-25, received a response on 2025-05-27, and Airoha distributed a fixed SDK to manufacturers on 2025-06-04, shortly before partial public disclosure around TROOPERS 2025 (2025-06-26). Full technical disclosure including the RACE Toolkit proof-of-concept followed in December 2025. Apple shipped the Beats Studio Buds fix as Beats Firmware Update 1B211, auto-delivered when the buds pair with an iPhone, iPad or Mac. While exploitation is realistic, ERNW assessed practical attacks as requiring technical sophistication and likely limited to high-value targets.

## MITRE ATT&CK

- T1592 Gather Victim Host Information
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1542.001 System Firmware
- T1684.001 Impersonation
- T1212 Exploitation for Credential Access
- T1552.001 Credentials In Files
- T1082 System Information Discovery
- T1120 Peripheral Device Discovery
- T1123 Audio Capture
- T1005 Data from Local System
- T1557 Adversary-in-the-Middle
- T1095 Non-Application Layer Protocol
- T1011.001 Exfiltration Over Bluetooth
- T1565.001 Stored Data Manipulation

## Sources

- [Apple fixes Beats Studio Buds flaw that let hackers spy on conversations](https://www.bleepingcomputer.com/news/security/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations/)
- [Security Advisory: Airoha-based Bluetooth Headphones and Earbuds](https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/)
- [Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities](https://insinuator.net/2025/12/bluetooth-headphone-jacking-full-disclosure-of-airoha-race-vulnerabilities/)
- [RACE Toolkit (proof-of-concept exploitation tool)](https://github.com/auracast-research/race-toolkit)
- [Airoha Chip Vulns Put Sony, Bose Earbuds & Headphones at Risk](https://www.darkreading.com/vulnerabilities-threats/airoha-chip-vulns-sony-bose-earbuds-headphones)
- [Bluetooth flaws could let hackers spy through your microphone](https://www.bleepingcomputer.com/news/security/bluetooth-flaws-could-let-hackers-spy-through-your-microphone/)
- [NVD - CVE-2025-20702](https://nvd.nist.gov/vuln/detail/CVE-2025-20702)
- [Tenable - CVE-2025-20701](https://www.tenable.com/cve/CVE-2025-20701)
- [Tenable - CVE-2025-20700](https://www.tenable.com/cve/CVE-2025-20700)
- [Airoha Product Security Bulletin 2025](https://www.airoha.com/product-security-bulletin/2025)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0850
