苹果更新了Beats Studio Buds无线耳机固件,修复了一个高危漏洞(CVE-2025-20701)。该漏洞允许附近攻击者通过蓝牙冒充已配对设备,窃听用户对话。修复固件版本为1B211,会自动安装到与iPhone、iPad或Mac配对的耳机上。
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.
The vulnerability, CVE-2025-20701, allowed improper authentication in the firmware running on the Bluetooth-related chips, which made it possible for people within signal range to impersonate devices that had previously been paired with the earbuds. The researchers demonstrated this in a series of end-to-end attacks that allowed them to eavesdrop on conversations or sounds within earshot of the phone microphone.
Apple joins the patch party
“Impact: An attacker within Bluetooth range may be able to listen through the microphone of a device which is not yet paired and actively seeking pair requests,” Apple said in a Tuesday security advisory. The fix is contained in Beats Firmware Update 1B211, which is delivered automatically while headphones are paired with and within Bluetooth range of a user’s iPhone, iPad, or Mac. Users can check their firmware version by going to Settings on their device, navigating to Bluetooth, and tapping the info button next to the headphones.Read full article
Comments
在移动操作系统竞争日趋白热化的当下,谷歌(Google)再次以稳健而系统的节奏推进其生态版图。本周,这家以搜索与广告起家的科技巨头正式推出 Android 17 与 Wear OS 7,同时完成一轮被称为 Pixel Drop 的设备更新,将最新一代人工智能模型深度植入自有硬件。这一系列动作并非孤立的功能叠加,而是围绕效率、安全与家庭场景展开的整体升级,试图在碎片化的终端环境中建立更统一的体验标准。