New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone
Security vulnerabilities have been discovered in Bluetooth headphones and earbuds using Airoha Bluetooth System-on-Chips (SoCs), which are prevalent in devices from manufacturers such as Sony, Bose, JBL, Marshall, and Jabra. These vulnerabilities could…
Security vulnerabilities have been discovered in Bluetooth headphones and earbuds using Airoha Bluetooth System-on-Chips (SoCs), which are prevalent in devices from manufacturers such as Sony, Bose, JBL, Marshall, and Jabra. These vulnerabilities could enable attackers to intercept conversations, access sensitive information, and control connected smartphones.
CVE-2025-20700 : Missing Authentication (BLE) with a CVSS Score of 8.8 . CVE-2025-20701 : Missing Authentication (Classic) with a CVSS Score of 8.8 . CVE-2025-20702 : RACE Protocol RCE / Arbitrary Read with a CVSS Score of 9.6 .
The vulnerabilities were disclosed in Jun 2025, yet many devices remain unpatched. As a result, full technical details, a white paper, and the RACE Toolkit have been released to assist users and security professionals in assessing their devices.
Airoha's Bluetooth SoCs, common in True Wireless Stereo (TWS) earbuds, expose a protocol called RACE (Remote Access Control Engine) over Bluetooth Low Energy, Bluetooth Classic, and USB HID connections. Originally intended for debugging and firmware updates, RACE can read and write to memory locations.
These vulnerabilities could enable attackers to intercept conversations, access sensitive information, and control connected smartphones.
The vulnerabilities allow attackers unauthorized access to Bluetooth services:
CVE-2025-20700 allows silent connections to the RACE protocol over Bluetooth Low Energy without user notification. CVE-2025-20701 enables two-way audio connections via Bluetooth Classic, potentially facilitating eavesdropping. CVE-2025-20702 exposes device information and memory, allowing for data extraction and device manipulation.
Potential Impacts on Connected Devices
The vulnerabilities can be exploited to target connected smartphones, allowing attackers to extract paired device information and cryptographic Link Keys. This enables impersonation of trusted devices and potential attacks, such as accessing contacts, using voice assistants, and intercepting calls.
Vulnerable devices include Sony WH and WF series headphones, Bose QuietComfort Earbuds, JBL Live Buds 3, Marshall MAJOR V and MINOR IV, and models from Beyerdynamic, Jabra, and Teufel. Some manufacturers have released firmware updates addressing these issues, with Jabra providing detailed information on affected devices and updates.
Users should update their devices through manufacturer applications or websites, consider using wired headphones, and remove unused paired devices to mitigate risks. Manufacturers must promptly implement Airoha's SDK patches and conduct thorough security assessments to prevent similar vulnerabilities in future products.
Based on reporting by Cyber Security News.
