Security researchers have identified and disclosed several critical vulnerabilities in Bluetooth headphones and earbuds powered by Airoha Bluetooth System-on-Chips (SoCs), which are widely used by major brands such as Sony, Bose, JBL, Marshall, and Jabra. The vulnerabilities, tracked as CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702, allow attackers within Bluetooth range to eavesdrop on conversations, steal sensitive data, and potentially hijack connected smartphones. The most severe flaw, related to the RACE (Remote Access Control Engine) protocol, enables remote code execution and arbitrary memory access due to missing authentication mechanisms in both Bluetooth Low Energy and Classic modes. Despite initial disclosure in June 2025 and the availability of patches, many affected devices remain unpatched, increasing the risk of exploitation.
The RACE protocol, originally designed for factory debugging and firmware updates, is exposed over multiple interfaces, including Bluetooth and USB HID, providing attackers with powerful capabilities if exploited. Researchers have released a white paper and the RACE Toolkit to help users and security professionals assess device vulnerability. The ongoing exposure of these flaws highlights the importance of timely patching and the risks associated with insecure default configurations in widely deployed consumer electronics. Users of affected headphones and earbuds are urged to check for firmware updates and apply patches as soon as possible to mitigate the risk of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Media reports publicized the vulnerabilities as 'Headphone Jacking,' emphasizing that affected earbuds and headphones from brands such as Sony, Bose, JBL, Marshall, and Jabra could be used to compromise connected phones. The coverage noted proof-of-concept attacks involving account compromise and warned that many devices were still unpatched.
Researchers later released technical details and a toolkit to help users assess exposure to the Bluetooth headphone vulnerabilities. The published material described how attackers within Bluetooth range could eavesdrop, steal data, extract keys, and hijack connected smartphones.
Following the disclosure, some manufacturers including Jabra, Marshall, and Beyerdynamic released firmware updates to address the Airoha-based vulnerabilities in affected devices. Patch coverage varied across brands, and transparency about fixes remained inconsistent.
Security researchers initially disclosed multiple vulnerabilities affecting Bluetooth headphones and earbuds using Airoha SoCs, including issues tied to the RACE protocol and missing authentication. The disclosure occurred in June 2025, starting remediation efforts by vendors and manufacturers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.