A Bluetooth chipset installed in popular models from major manufacturers is vulnerable. Hackers could use it to initiate calls and monitor devices.
The connection between wireless headphones and smartphones is the target of the new Bluetooth attack.
A Bluetooth chipset installed in popular models from major manufacturers is vulnerable. Hackers could use it to initiate calls and monitor devices.
The connection between wireless headphones and smartphones is the target of the new Bluetooth attack.
A serious security vulnerability in many Bluetooth headsets allows attackers to listen to data from the devices remotely and take control of connections, researchers at German security firm ERNW have discovered , presenting their findings at this year's TROOPERS security conference.
Researchers suspect that millions of devices from various manufacturers are affected. There are currently no updates available to fix the problem.
The vulnerabilities are found in the Bluetooth SoC (System-on-Chip) of Taiwanese manufacturer Airoha, which is particularly popular for its “True Wireless Stereo” (TWS) headphones. Using Airoha chips, the small in-ear headphones can reproduce stereo sound from playback devices such as smartphones without delay. Well-known manufacturers such as Sony, JBL, Marshall and Bose use it in some cases, but also install Bluetooth technology from other suppliers.
Vulnerable devices:
Airoha has given its Bluetooth chips a custom protocol that allows them to manage the working memory and flash memory of devices over the air. The protocol, which is accessible via Bluetooth Low Energy (BLE) as well as “classic” Bluetooth (BD/EDR), is likely intended for interaction with manufacturer applications, but it’s also an invitation for curious security researchers.
This allowed them to remotely control headphones from various manufacturers – without connecting to an app or using the usual Bluetooth “pairing.” By gaining full access to the headphones’ flash memory and RAM, they were also able to take over connections to other devices, such as the actual user’s smartphone.
By accessing the working memory of the Bluetooth chip, the researchers could initially "read" what media the user was currently playing, such as a podcast or a music track.
However, the attack is laborious: since memory addresses differ from device to device, the researchers couldn't simply read random data on a crowded bus, and had to adapt their attack. On Android devices, the experts were also able to read the device's phone number and incoming calls, sometimes even the phone's call history and address book.
The researchers were able to take over the connection between the phone and the headphones by copying the Bluetooth connection cryptographic key from the headphones.
They then have many options – they can initiate or reject calls, activate voice assistants like Siri and Gemini, and track the victim using a multitude of methods.
In a monitoring attack, attackers impersonate the connected smartphone to the headphones and redirect the recorded audio from their microphone. However, this attack is easy to detect. The victim suddenly stops listening to music or hears something suspicious through their headphones.
The second method simulates a headset on the phone and tricks it into making a call to the attackers. If the victim is not paying attention to their smartphone, Bluetooth spies can now listen to everything that happens within range of the device.
Although these attacks seem scary, ERNW researchers are reassuring: several conditions must be met for an eavesdropping attack to take place.
First of all, the attacker would have to be within the short-range Bluetooth range. An attack over the Internet is not possible. They would also have to perform several technical steps without attracting attention. And they would have to have a reason to intercept the Bluetooth connection, which, according to the researchers, is only possible for a few targeted individuals.
Examples of potential targets include celebrities, journalists or diplomats, but also political dissidents, employees at security-critical companies and others.
CVE-2025-20702: CVSS 9.6/10 (critical risk): Critical features of the proprietary Airoha protocol
CVE-2025-20700: CVSS 8.8/10 (high risk): Missing authentication for GATT service
CVE-2025-20701: CVSS 8.8/10 (high risk): Missing authentication for Bluetooth pairing
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.