Bluetooth Flaws Could Let Hackers Spy Through Your Microphone | Vulnerabilities in Airoha Chips Explained
Discover how critical Bluetooth vulnerabilities in Airoha chipsets found in top brands like Bose, Sony, and JBL could let attackers eavesdrop, steal data, and hijack calls. Learn how to stay protected.
Table of Contents
- Why this matters
- The vulnerabilities
- Attack flow in the wild
- Mitigation status
- What you can do right now
- Bigger picture: Bluetooth’s long tail of risk
- Conclusion
- Frequently Asked Questions (FAQs)
Bluetooth security just took a hit. Three newly disclosed flaws in Airoha Bluetooth chips let an attacker in radio range hijack popular headphones, earbuds, speakers — and even spy on the smartphone that’s paired to them. Below is a practical rundown of what happened, which devices are at risk, and what you can do while vendors roll out fixes.
Why this matters
-
29 products from ten well‑known brands (Bose, Sony, Jabra, JBL, Beyerdynamic, Marshall, Teufel, JLab, EarisMax, MoerLabs) embed the vulnerable Airoha SoC.
-
A successful attack lets a hacker read what you’re listening to, trigger calls, grab contacts or call history, and eavesdrop through the phone’s microphone without ever pairing to the headset.
-
Although exploitation requires Bluetooth‑range proximity (~10 m) and solid reverse‑engineering skills, the stakes are high for journalists, diplomats, executives, or anyone handling sensitive calls.
The vulnerabilities
| CVE | CVSS v3 Score | Root cause | Practical impact |
|---|---|---|---|
| CVE‑2025‑20700 | 6.7 (Med) | No authentication on GATT services | Read / write data over BLE |
| CVE‑2025‑20701 | 6.7 (Med) | No auth on BR/EDR profile | Classic‑Bluetooth commands without pairing |
| CVE‑2025‑20702 | 7.5 (High) | Flaws in a custom vendor protocol | Dump link keys → hijack connection, launch calls |
ERNW researchers unveiled proof‑of‑concept code at TROOPERS 25 showing how they pulled the currently playing song from a Bose headset, then escalated to dial an arbitrary number from the victim’s phone and listen in.
Attack flow in the wild
-
Get close – The attacker sits in a café or boarding gate within Bluetooth range.
-
Sniff & identify – They spot the Airoha chipset’s MAC fingerprint.
-
Memory dump – Using CVE‑2025‑20702 they extract the Bluetooth link keys stored in the headset.
-
Impersonate the device – The phone reconnects to the attacker’s rogue hardware.
-
Issue HFP commands – Calls are placed or answered silently; contacts and history are pulled via AT commands.
-
Listen live – Conversation audio is streamed to the attacker. If firmware rewriting is possible, a wormable payload could spread the exploit to every nearby vulnerable headset.
Mitigation status
-
Airoha released an updated SDK with authentication checks and patched protocol handlers in mid‑June 2025.
-
Vendors are baking the fixes into firmware, but German outlet Heise notes that half the affected products still ship May‑2025 (pre‑patch) firmware.
-
OS vendors (Android / iOS) can’t fully block the issue because the exploit runs inside the peripheral, not the phone.
What you can do right now
| Action | Why it helps |
|---|---|
| Update firmware | Check the headphone/earbud companion app weekly until a security bulletin appears. |
| Disable Bluetooth discoverability | Makes it harder to fingerprint your device in public. |
| Unpair in crowded areas | Turn off Bluetooth or use wired mode when handling sensitive calls. |
| Watch for phantom calls | Unexpected outgoing or answered calls may signal compromise. |
| Favor headsets with secure‑element chips | Newer models store link keys in hardware, resisting memory dumps. |
Bigger picture: Bluetooth’s long tail of risk
Bluetooth’s 10‑meter convenience also grants attackers physical access without needing to touch a device. Previous headline issues (BLURtooth, KNOB, BlueBorne) show that legacy protocol assumptions keep breaking as researchers push fuzzers and AI‑guided reverse‑engineering against closed‑source firmwares.
Regulators have noticed:
-
FCC SIM‑swap & port‑out rules (2023) already push carriers toward stronger identity checks; similar pressure on Bluetooth vendors is likely next.
-
EU Cyber‑Resilience Act (CRA) will require consumer IoT makers to maintain timely security updates — headphones included — or face fines.
Conclusion
While the newly disclosed Airoha flaws require skill and proximity, they underline a recurrent theme: peripheral security is mobile security. Until every vendor delivers patched firmware, treat wireless audio gear like any other untrusted radio device—keep it updated, limit its exposure, and stay alert for unusual behavior.
Stay safe, stay patched, and keep an ear out for firmware notices from your headphone maker. The privacy of your next call could depend on it.
FAQs:
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0