New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones
Security researchers have identified critical vulnerabilities in Airoha-based Bluetooth headphones, which allow attackers to compromise connected smartphones through chained exploits.
Security researchers have identified critical vulnerabilities in Airoha-based Bluetooth headphones, which allow attackers to compromise connected smartphones through chained exploits.
The vulnerabilities CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702 affect multiple popular headphone models from manufacturers such as Sony, Marshall, Jabra, and Bose. These issues arise from missing authentication mechanisms and exposed debugging functionality in Airoha's RACE protocol, which is used for device configuration and firmware updates.
CVE-2025-20700: Allows unauthenticated Bluetooth Low Energy connections. CVE-2025-20701: Permits unauthorized Bluetooth Classic connections. CVE-2025-20702: Provides arbitrary read and write access to device memory via the RACE protocol.
Attackers can exploit these vulnerabilities to establish unauthenticated connections, extract sensitive information like the Bluetooth Link Key, and impersonate trusted headphones. This access enables them to execute various attacks, including accessing contact lists, making calls, and extracting location data on unlocked devices. Additionally, call hijacking and eavesdropping are possible by initiating calls to attacker-controlled numbers.
CVE-2025-20700: Allows unauthenticated Bluetooth Low Energy connections.
At least 30 device models are confirmed vulnerable, including Sony WF-1000XM5 and JBL Live Buds 3, among others. While some vendors, like Jabra, have implemented patches, others have not publicly addressed these vulnerabilities. Airoha released SDK patches in June 2025, but vendor update adoption is inconsistent. Users are advised to update their devices and remove old pairings.
Researchers suggest high-value targets consider using wired headphones to mitigate risk. Manufacturers are advised to apply Airoha patches and conduct security assessments using established Bluetooth security testing methodologies. The release of a white paper and the RACE Toolkit allows users to verify device vulnerability status independently.
Technical details were disclosed responsibly, six months post-initial notification, to provide vendors ample time for patching.
Based on reporting by GBHackers.
