Observed Signal · Jun 17, 2026 · Security Patch · Source: t3n · Impact: 4/5 · Sentiment: Neutral
Beats Studio Buds Bluetooth Bug Enabled Microphone Eavesdropping
A security flaw in Apple’s Beats Studio Buds (released 2021) allowed attackers within Bluetooth range to take control of the earbuds and listen via their built-in microphone. Apple released firmware 1B211 on June 17, 2026 to close the issue, which is tracked as CVE-2025-20701. The root cause was a missing authentication step in a third‑party Bluetooth audio SDK from Airoha/MediaTek; Airoha says a required GATT authentication was absent. Security researchers Dennis Heinze and Frieder Steinmetz of ERNW discovered the vulnerability. Apple’s advisory names only the Studio Buds as affected and does not mention the 2023 Studio Buds Plus. Users receive the update automatically when the earbuds are connected to an iPhone, iPad or Mac; it remains unclear whether the flaw was exploited in the wild.
Firmware security fixes from a major platform (Apple) matter to the broader ecosystem: they highlight supply‑chain SDK risks (Airoha/MediaTek), affect user privacy expectations for consumer audio devices, and influence firmware distribution practices.
Track Apple Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Apple released firmware 1B211 for Beats Studio Buds to fix a security vulnerability (CVE-2025-20701).
- The flaw allowed attackers in Bluetooth range to hijack Beats Studio Buds and use their microphones to eavesdrop.
- The vulnerability originated in a third‑party Bluetooth audio SDK from Airoha/MediaTek that lacked a GATT authentication step.
- Security researchers Dennis Heinze and Frieder Steinmetz of ERNW discovered the issue.
- Apple's advisory lists only the 2021 Studio Buds as affected; Studio Buds Plus (2023) is not mentioned.
Connected Companies & Entities
3 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Apple fixes iOS 26 zero-click security flaws
Apple has patched two critical security vulnerabilities affecting iOS 26, iPadOS 26, and macOS 26. The first, CVE-2026-86950, is a graphics engine bug that may have been exploited in highly sophisticated attacks. The second, CVE-2026-86869, is a zero-click iMessage vulnerability that could bypass BlastDoor, discovered by Belgian firm ironPeak and Meta. Apple credited Meta's product security team and ironPeak's Niels Hofmans. Both vulnerabilities affect a large user base still on iOS 26, though iOS 27 devices are unaffected. Details remain limited, and it's unknown if the flaws were actively exploited.
Unpatchable BootROM USB Flaw in A12/A13 Apple Chips
Security researchers at Paradigm Shift disclosed a BootROM vulnerability called “usbliter8” affecting Apple A12 and A13 family chips and Apple Watch S4/S5 processors. The flaw resides in the USB controller (Synopsys DWC2) inside the immutable BootROM, so Apple cannot patch it with a software update. Paradigm Shift published a proof-of-concept on GitHub that uses a modified Waveshare USB-A board (or compatible RP2350 boards) connected via cable; exploitation requires physical access to the device. The bug can let specially crafted USB packets corrupt the controller’s buffer and access protected memory, potentially enabling full device takeover. A12X/A12Z are suspected vulnerable but not confirmed; A11 is unaffected. Researchers expect a full jailbreak could follow, and recommend upgrading hardware as the primary mitigation.
Apple Patches 100+ Security Flaws in iOS 27 and macOS 27
Apple released iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 on September 14, 2026, fixing over 100 security vulnerabilities in iOS 27 alone. Critical issues include a Bluetooth vulnerability allowing arbitrary code execution and app crashes, and a baseband modem flaw enabling remote denial-of-service attacks. Apple credits AI tools like Anthropic Claude and OpenAI Codex Security for assisting researchers in finding these bugs. Older OS versions (iOS 26.7, macOS 26.7, macOS 15.8) received partial fixes, but Intel Macs are excluded from macOS 27. Additionally, Safari 27 was released for older macOS versions to address WebKit vulnerabilities, and users are advised to upgrade for full protection.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
