Researchers disclosed three vulnerabilities in Bluetooth audio devices built on Airoha systems-on-chip that can allow an attacker within radio range to gain unauthorized access to device memory and communications. The flaws, tracked as CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702, stem from missing authentication in GATT and Bluetooth BR/EDR components and weak permission controls in a proprietary protocol, affecting headphones and earbuds sold by brands including Sony, Bose, Jabra, JBL, Marshall, Beyerdynamic, and Teufel.
ERNW researchers said the bugs can be chained to hijack the Bluetooth link between a phone and an audio device, issue commands to the paired phone through the Hands-Free Profile, eavesdrop on conversations, and potentially overwrite firmware for remote code execution on the accessory. The attack requires proximity because exploitation is limited by Bluetooth range, but defenders were urged to apply vendor firmware updates and investigate or restart devices showing abnormal Bluetooth behavior.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published a warning about the Airoha Bluetooth vulnerabilities and advised users to update device firmware and restart devices if Bluetooth connectivity behaves abnormally. The notice also emphasized that practical exploitation is limited by Bluetooth range, roughly 10 meters under ideal conditions.
The published advisory explained that chaining the three vulnerabilities could let an attacker within Bluetooth range hijack the connection between a phone and an audio device, send commands via the Hands-Free Profile, eavesdrop on conversations, and potentially overwrite firmware for remote code execution. Affected products were reported across brands including Sony, Bose, Jabra, JBL, Marshall, Beyerdynamic, and Teufel.
Researchers from the German company ERNW identified three flaws in Airoha systems-on-chip used in Bluetooth headphones and earbuds: CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702. The issues include missing authentication in GATT and Bluetooth BR/EDR and insufficient permission restrictions in a proprietary protocol.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.