Attack via Bluetooth headphones from Sony, Marshall, and Beyerdynamic using Airoha chips

Vulnerabilities have been identified in Bluetooth devices utilizing SoC from Airoha Systems, allowing control over the device through specially crafted data sent via Bluetooth Classic or BLE (Bluetooth Low Energy). The attack can be executed without authentication and without prior pairing, as long as the victim's device is within Bluetooth signal range (approximately 10 meters). The vulnerabilities affect certain models of wireless headphones, speakers, and microphones from Sony, Marshall, Beyerdynamic, and lesser-known companies.

Researchers who discovered the vulnerability were able to develop a prototype toolkit that allows reading and writing data to the RAM and Flash memory remotely via Bluetooth. In practice, gaining full access to the memory of the headphones could be used to attack the smartphone paired with the user's headphones. Specifically, it has been mentioned that through the interaction between the headphones and the smartphone, access to the contact list can be obtained, call history can be extracted, calls can be made, and conversations or sounds captured by the microphone can be intercepted.

The HFP (Hands-Free Profile) Bluetooth profile is used for interaction with smartphones from compromised headphones, allowing commands to be sent to the smartphone. Due to the complexity of exploiting the vulnerabilities, it can be assumed that these issues will be sought after for targeted attacks on specific individuals rather than for mass exploitation against average users. The problem is that the toolkit for executing the attack must be developed for each individual model of headphones, as the differences in memory layout in each firmware must be taken into account.

The attack is possible due to the discovery of three vulnerabilities in the Airoha Bluetooth stack. Vulnerabilities CVE-2025-20700 and CVE-2025-20701 allow establishing a communication channel with Bluetooth BR/EDR (Bluetooth Classic) and GATT services (Bluetooth Low Energy) without authentication, while vulnerability CVE-2025-20702 enables the use of a specific Airoha SoC extended protocol for device manipulation. Researchers found that the service's extended protocol, among other things, allows reading and writing data to RAM and Flash, and is accessible without pairing through BLE GATT or Bluetooth Classic RFCOMM.

Information about the vulnerabilities was sent to Airoha on March 25, but a response was only received on May 27 after several follow-ups and involvement from some device manufacturers. On June 4, Airoha began distributing an updated SDK to manufacturers that includes the means to block the vulnerabilities. At the end of June, after 90 days had passed since the vulnerability information was sent, researchers published general details about the vulnerabilities but decided not to disclose specifics regarding the problematic protocol yet, to give manufacturers additional time to roll out firmware updates.

Devices confirmed to have the mentioned vulnerabilities:

  • Beyerdynamic Amiron 300;
  • Bose QuietComfort Earbuds;
  • EarisMax Bluetooth Auracast Sender;
  • Jabra Elite 8 Active;
  • JBL Endurance Race 2, JBL Live Buds 3;
  • Jlab Epic Air Sport ANC;
  • Marshall ACTON III, MAJOR V, MINOR IV, MOTIF II, STANMORE III, WOBURN III;
  • MoerLabs EchoBeatz;
  • Sony CH-720N, Link Buds S, ULT Wear, WF-1000XM3/4/5, WF-C500, WF-C510-GFP, WH-1000XM4/5/6, WH-CH520, WH-XB910N, WI-C100;
  • Teufel Tatws2.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster