Bluetooth Flaws Could Let Hackers Spy Through Your Microphone | Vulnerabilities in Airoha Chips Explained

Discover how critical Bluetooth vulnerabilities in Airoha chipsets found in top brands like Bose, Sony, and JBL could let attackers eavesdrop, steal data, and hijack calls. Learn how to stay protected.

Jul 02, 2025 - 10:40
107.2k
Bluetooth Flaws Could Let Hackers Spy Through Your Microphone |  Vulnerabilities in Airoha Chips Explained

Table of Contents

Bluetooth security just took a hit. Three newly disclosed flaws in Airoha Bluetooth chips let an attacker in radio range hijack popular headphones, earbuds, speakers — and even spy on the smartphone that’s paired to them. Below is a practical rundown of what happened, which devices are at risk, and what you can do while vendors roll out fixes.

Why this matters

  • 29 products from ten well‑known brands (Bose, Sony, Jabra, JBL, Beyerdynamic, Marshall, Teufel, JLab, EarisMax, MoerLabs) embed the vulnerable Airoha SoC.

  • A successful attack lets a hacker read what you’re listening to, trigger calls, grab contacts or call history, and eavesdrop through the phone’s microphone without ever pairing to the headset.

  • Although exploitation requires Bluetooth‑range proximity (~10 m) and solid reverse‑engineering skills, the stakes are high for journalists, diplomats, executives, or anyone handling sensitive calls.

The vulnerabilities

CVE CVSS v3 Score Root cause Practical impact
CVE‑2025‑20700  6.7 (Med) No authentication on GATT services Read / write data over BLE
CVE‑2025‑20701  6.7 (Med) No auth on BR/EDR profile Classic‑Bluetooth commands without pairing
CVE‑2025‑20702  7.5 (High) Flaws in a custom vendor protocol Dump link keys → hijack connection, launch calls

ERNW researchers unveiled proof‑of‑concept code at TROOPERS 25 showing how they pulled the currently playing song from a Bose headset, then escalated to dial an arbitrary number from the victim’s phone and listen in.

Attack flow in the wild

  1. Get close – The attacker sits in a café or boarding gate within Bluetooth range.

  2. Sniff & identify – They spot the Airoha chipset’s MAC fingerprint.

  3. Memory dump – Using CVE‑2025‑20702 they extract the Bluetooth link keys stored in the headset.

  4. Impersonate the device – The phone reconnects to the attacker’s rogue hardware.

  5. Issue HFP commands – Calls are placed or answered silently; contacts and history are pulled via AT commands.

  6. Listen live – Conversation audio is streamed to the attacker. If firmware rewriting is possible, a wormable payload could spread the exploit to every nearby vulnerable headset.

Mitigation status

  • Airoha released an updated SDK with authentication checks and patched protocol handlers in mid‑June 2025.

  • Vendors are baking the fixes into firmware, but German outlet Heise notes that half the affected products still ship May‑2025 (pre‑patch) firmware.

  • OS vendors (Android / iOS) can’t fully block the issue because the exploit runs inside the peripheral, not the phone.

What you can do right now

Action Why it helps
Update firmware Check the headphone/earbud companion app weekly until a security bulletin appears.
Disable Bluetooth discoverability Makes it harder to fingerprint your device in public.
Unpair in crowded areas Turn off Bluetooth or use wired mode when handling sensitive calls.
Watch for phantom calls Unexpected outgoing or answered calls may signal compromise.
Favor headsets with secure‑element chips Newer models store link keys in hardware, resisting memory dumps.

Bigger picture: Bluetooth’s long tail of risk

Bluetooth’s 10‑meter convenience also grants attackers physical access without needing to touch a device. Previous headline issues (BLURtooth, KNOB, BlueBorne) show that legacy protocol assumptions keep breaking as researchers push fuzzers and AI‑guided reverse‑engineering against closed‑source firmwares.

Regulators have noticed:

  • FCC SIM‑swap & port‑out rules (2023) already push carriers toward stronger identity checks; similar pressure on Bluetooth vendors is likely next.

  • EU Cyber‑Resilience Act (CRA) will require consumer IoT makers to maintain timely security updates — headphones included — or face fines.

Conclusion

While the newly disclosed Airoha flaws require skill and proximity, they underline a recurrent theme: peripheral security is mobile security. Until every vendor delivers patched firmware, treat wireless audio gear like any other untrusted radio device—keep it updated, limit its exposure, and stay alert for unusual behavior.

Stay safe, stay patched, and keep an ear out for firmware notices from your headphone maker. The privacy of your next call could depend on it.

FAQs:

Recent flaws were found in Airoha Bluetooth chips used in popular headphones and earbuds, allowing attackers to eavesdrop and control connected smartphones.

The vulnerabilities are CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702.

Two vulnerabilities are rated medium (6.7), and one is rated high (7.5) by CVSS.

By extracting Bluetooth link keys from memory, attackers can impersonate the headset and hijack the smartphone connection.

Yes, they can trigger calls and listen through the phone's microphone by exploiting Bluetooth Hands-Free Profile (HFP).

The vulnerabilities exist in Airoha SoCs, commonly used in audio devices.

Brands like Bose, Sony, JBL, Jabra, Marshall, and more are affected.

The attacker must be within standard Bluetooth range, roughly 10 meters.

No, it requires physical proximity but no prior pairing.

ERNW researchers demonstrated playback sniffing and remote call initiation at a security conference.

Link keys are cryptographic credentials that secure Bluetooth pairings between devices.

They use vulnerabilities in the firmware to dump memory and retrieve the keys.

Yes, by mimicking a connected headset, attackers can issue call commands.

Yes, in some phone configurations, attackers can retrieve call history and contact data.

Check the model and firmware version, and consult the manufacturer's security updates.

Yes, Airoha has released an SDK fix, but device vendors need to push firmware updates.

No known public attacks yet, but proof-of-concept exists and is credible.

Both platforms are vulnerable depending on how they handle HFP connections.

Ensure your device firmware is updated, and disable Bluetooth when not in use.

Patches may be in development; check official support sites for updates.

Yes, researchers say a wormable version of the attack is theoretically possible.

It turns a trusted audio device into a potential surveillance tool.

HFP is a Bluetooth profile that allows headsets to control phone functions like calling.

Yes, many speakers using Airoha chips are also vulnerable.

They can potentially issue commands to the phone via a spoofed headset.

By releasing timely firmware patches and enforcing secure memory handling.

Likely for years, but it was disclosed in mid-2025 at the TROOPERS conference.

No, most mobile security tools don't monitor Bluetooth hardware behavior.

Yes, disabling Bluetooth when not in use reduces exposure.

Check the official support page of your headphone or speaker manufacturer.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.