Tuesday, September 8, 2026

New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones

Security researchers have disclosed critical vulnerabilities in Airoha-based Bluetooth headphones that enable attackers to compromise connected smartphones through chained exploits.

The three vulnerabilities CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702 affect dozens of popular headphone models from Sony, Marshall, Jabra, Bose, and other manufacturers.

The vulnerabilities center on missing authentication mechanisms and exposed debugging functionality in Airoha’s custom RACE protocol, which is used for device configuration and firmware updates.

Attackers within Bluetooth range can exploit these flaws without requiring prior pairing or user interaction.

The Attack Chain

The exploitation begins with unauthenticated connection establishment. CVE-2025-20700 allows attackers to connect via Bluetooth Low Energy without authentication, while CVE-2025-20701 permits unauthorized Bluetooth Classic connections.

Once connected, attackers leverage CVE-2025-20702 to access the RACE protocol, which provides arbitrary read and write access to device memory.

Using these capabilities, attackers can extract the Bluetooth Link Key the cryptographic secret shared between headphones and paired smartphones.

According to Insinuator, Researchers demonstrated that this key enables attackers to impersonate trusted headphones to the victim’s phone, gaining a privileged position on the device.

From this privileged state, attackers can execute multiple attacks. Using the Bluetooth Hands-Free Profile, they can access phone numbers, contact lists, and call history.

More critically, attackers can trigger voice assistants to send messages, make calls, or extract location data on unlocked devices.

The vulnerabilities also enable call hijacking, where attackers silently accept incoming calls and capture audio streams, or eavesdropping by initiating calls to attacker-controlled numbers using the victim’s phone.

The vulnerability survey identified at least 30 vulnerable devices, including Sony WF-1000XM5, Marshall ACTON III, JBL Live Buds 3, and Beyerdynamic Amiron 300.

However, researchers note this represents only verified devices, with potentially many more affected models remaining unpatched.

Notably, some vendors like Jabra implemented additional security measures and patched their devices, while others including Sony and Bose have not publicly addressed the vulnerabilities.

Airoha released SDK patches in June 2025, but vendor adoption remains inconsistent. Users should immediately update their devices and remove old paired devices from their phones.

Researchers recommend high-value targets like journalists and diplomats consider using wired headphones instead.

RACE protocol
RACE protocol

The researchers released a white paper and the RACE Toolkit, enabling users to verify device vulnerability status independently.

USD packet
USD packet

Manufacturers are urged to apply Airoha patches and conduct security assessments before product release using established Bluetooth security testing methodologies.

The disclosure follows responsible disclosure practices, with technical details released six months after initial notification to allow vendors adequate patching time.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Related Articles

Recent News