Affected Systems
Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).
Exploitation Status
No public reports of active exploitation. Attack requires physical proximity to target device. No public PoC available at this time.
Business Impact
Attackers within Bluetooth range can pair to vulnerable Beats Studio Buds without user consent and activate the microphone for eavesdropping. Primary risk is unauthorized audio surveillance in corporate environments, executive meetings, or sensitive areas. Consumer privacy impact is high; enterprise risk depends on device deployment and physical security posture.
Urgency
🟡 Within a week
Recommended Actions
- Apply Apple firmware update for Beats Studio Buds immediately via iOS/iPadOS Settings > Bluetooth > device info, or macOS System Settings
- Inventory corporate-issued or BYOD Beats Studio Buds in use by executives and employees with access to sensitive information
- Disable Bluetooth on Beats Studio Buds when not actively in use, especially in high-security areas or during confidential meetings
- Review Bluetooth device pairing logs on corporate mobile devices for unexpected connections to audio peripherals
- Implement or reinforce policies prohibiting Bluetooth audio devices in classified or restricted meeting spaces
