Bluetooth 0-day turns headphones into listening stations

A Bluetooth chipset installed in popular models from major manufacturers is vulnerable. Hackers could use it to initiate calls and monitor devices.

The connection between wireless headphones and smartphones is the target of the new Bluetooth attack.

See more articles from iGuRu.gr when you search for news on Google.

A serious security vulnerability in many Bluetooth headsets allows attackers to listen to data from the devices remotely and take control of connections, researchers at German security firm ERNW have discovered , presenting their findings at this year's TROOPERS security conference.

Researchers suspect that millions of devices from various manufacturers are affected. There are currently no updates available to fix the problem.

The vulnerabilities are found in the Bluetooth SoC (System-on-Chip) of Taiwanese manufacturer Airoha, which is particularly popular for its “True Wireless Stereo” (TWS) headphones. Using Airoha chips, the small in-ear headphones can reproduce stereo sound from playback devices such as smartphones without delay. Well-known manufacturers such as Sony, JBL, Marshall and Bose use it in some cases, but also install Bluetooth technology from other suppliers.

Affected Devices

Vulnerable devices:

  • Beyerdynamic Amiron 300
  • Bose QuietComfort earbuds
  • EarisMax Bluetooth Auracast Sender
  • Jabra Elite 8 Active
  • JBL Endurance Race 2
  • JBL Live Buds 3
  • Jlab Epic Air Sport ANC
  • Marshall ACTON III
  • Marshall Major V
  • Marshall MINOR IV
  • Marshall MOTIF II
  • Marshall STANMORE III
  • Marshall WOBURN III
  • MoerLabs EchoBeatz
  • Sony CH-720N
  • Sony Link Buds S
  • Sony ULT Wear
  • Sony WF-1000XM3
  • Sony WF-1000XM4
  • Sony WF-1000XM5
  • Sony WF-C500
  • Sony WF-C510-GFP
  • Sony WH-1000XM4
  • Sony WH-1000XM5
  • Sony WH-1000XM6
  • SonyWH-CH520
  • Sony WH-XB910N
  • Sony WI-C100
  • Devil Tattoos2

Airoha has given its Bluetooth chips a custom protocol that allows them to manage the working memory and flash memory of devices over the air. The protocol, which is accessible via Bluetooth Low Energy (BLE) as well as “classic” Bluetooth (BD/EDR), is likely intended for interaction with manufacturer applications, but it’s also an invitation for curious security researchers.

This allowed them to remotely control headphones from various manufacturers – without connecting to an app or using the usual Bluetooth “pairing.” By gaining full access to the headphones’ flash memory and RAM, they were also able to take over connections to other devices, such as the actual user’s smartphone.

By accessing the working memory of the Bluetooth chip, the researchers could initially "read" what media the user was currently playing, such as a podcast or a music track.

However, the attack is laborious: since memory addresses differ from device to device, the researchers couldn't simply read random data on a crowded bus, and had to adapt their attack. On Android devices, the experts were also able to read the device's phone number and incoming calls, sometimes even the phone's call history and address book.

The researchers were able to take over the connection between the phone and the headphones by copying the Bluetooth connection cryptographic key from the headphones.

They then have many options – they can initiate or reject calls, activate voice assistants like Siri and Gemini, and track the victim using a multitude of methods.

In a monitoring attack, attackers impersonate the connected smartphone to the headphones and redirect the recorded audio from their microphone. However, this attack is easy to detect. The victim suddenly stops listening to music or hears something suspicious through their headphones.

The second method simulates a headset on the phone and tricks it into making a call to the attackers. If the victim is not paying attention to their smartphone, Bluetooth spies can now listen to everything that happens within range of the device.

Although these attacks seem scary, ERNW researchers are reassuring: several conditions must be met for an eavesdropping attack to take place.

First of all, the attacker would have to be within the short-range Bluetooth range. An attack over the Internet is not possible. They would also have to perform several technical steps without attracting attention. And they would have to have a reason to intercept the Bluetooth connection, which, according to the researchers, is only possible for a few targeted individuals.

Examples of potential targets include celebrities, journalists or diplomats, but also political dissidents, employees at security-critical companies and others.

Airoha has assigned a total of three CVE IDs for the vulnerabilities:

CVE-2025-20702: CVSS 9.6/10 (critical risk): Critical features of the proprietary Airoha protocol
CVE-2025-20700: CVSS 8.8/10 (high risk): Missing authentication for GATT service
CVE-2025-20701: CVSS 8.8/10 (high risk): Missing authentication for Bluetooth pairing


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).