苹果更新了Beats Studio Buds无线耳机固件,修复了一个高危漏洞(CVE-2025-20701)。该漏洞允许附近攻击者通过蓝牙冒充已配对设备,窃听用户对话。修复固件版本为1B211,会自动安装到与iPhone、iPad或Mac配对的耳机上。
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.
The vulnerability, CVE-2025-20701, allowed improper authentication in the firmware running on the Bluetooth-related chips, which made it possible for people within signal range to impersonate devices that had previously been paired with the earbuds. The researchers demonstrated this in a series of end-to-end attacks that allowed them to eavesdrop on conversations or sounds within earshot of the phone microphone.
Apple joins the patch party
“Impact: An attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired and actively seeking pair requests,” Apple said in a Tuesday security advisory. The fix is contained in Beats Firmware Update 1B211, which is delivered automatically while headphones are paired with and within Bluetooth range of a user’s iPhone, iPad, or Mac. Users can check their firmware version by going to Settings on their device, navigating to Bluetooth, and tapping the info button next to the headphones.Read full article
Comments
At the end of August, NASA is set to launch the Nancy Grace Roman Space Telescope from Kennedy Space Center in Florida. Its quest is to help us better understand how the universe works, from the glue-like dark matter that keeps galaxies together to the elusive dark energy that drives the expansion o...
This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology.
NASA’s new dark energy space telescope can also detect killer asteroids
At the end of August, NASA is set to launch the Nancy Grace Roman Space Telescope ...
Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was acc...
This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology.
Google’s AI empire is being reshaped. Here’s what’s changed.
After a wave of painful losses in the tech talent wars, delays to its next flagship model, and ...