Security researchers disclosed two Bluetooth firmware vulnerabilities in Xiaomi Redmi Buds models 3 Pro through 6 Pro that can be exploited by an attacker within radio range without pairing or authentication. The issues stem from how the earbuds handle RFCOMM control/signaling, including monitoring of undocumented internal channels beyond standard profiles like HFP and A2DP.
The first flaw, CVE-2025-13834, is an information disclosure bug likened to Heartbleed: a crafted RFCOMM TEST command with a manipulated/oversized length can trigger an out-of-bounds read and return up to 127 bytes of uninitialized memory, potentially exposing sensitive data such as phone numbers of active call peers. The second, CVE-2025-13328, is a denial-of-service condition where flooding control or service channels with TEST commands or signaling frames exhausts the processing queue, causing a firmware crash and disconnect; reporting indicates recovery may require a physical reset (e.g., placing earbuds back in the charging case), and at least one account notes no patch was available at the time of publication.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
At the time the vulnerabilities were publicly reported, Xiaomi had not released a patch or remediation guidance for the affected Redmi Buds devices. Users were advised to reduce exposure by disabling Bluetooth when the earbuds were not in use, especially in public places.
CERT/CC reported that CVE-2025-13834 can expose up to 127 bytes of uninitialized memory, including call-related data, and that CVE-2025-13328 can exhaust resources and force persistent disconnects until the earbuds are reset in their charging case. The disclosure also noted exploitation was demonstrated from about 20 meters using standard Bluetooth equipment.
Security researchers found two Bluetooth-range vulnerabilities affecting Xiaomi Redmi Buds models from Redmi Buds 3 Pro through 6 Pro. The flaws allow unauthenticated nearby attackers to leak uninitialized memory via RFCOMM and crash firmware through control-channel flooding without pairing or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.