Apple has released a firmware update for its Beats Studio Buds that fixes a high-severity Bluetooth security flaw. Multiple outlets report that the issue could allow an attacker within Bluetooth range to use the earbuds’ microphone to listen to nearby conversations and potentially access related information such as call history. The vulnerability is described as involving incorrect authorization in a Bluetooth audio implementation: it affects pairing behavior and can be triggered when the earbuds are unpaired and actively seeking pair requests. In this state, an attacker nearby may be able to pair or access the microphone without user consent.

The firmware update is identified as version 1B211. Sources describe that Apple’s fix is delivered when users connect the earbuds to an iPhone, iPad, or Mac and keep them on a charger while the devices are within Bluetooth range of the paired hardware. One report notes that the flaw has been tracked under CVE-2025-20701, with a high CVSS score. Several outlets also characterize this as a delayed patch, with the underlying issue reported to have existed for around a year before Apple’s fix was released.