CVE-2025-20700 is a missing-authentication vulnerability in the Airoha Bluetooth audio SDK affecting Bluetooth Low Energy GATT services. The flaw exposes access to the proprietary RACE protocol over BLE without requiring pairing or other authentication, allowing a nearby attacker to discover and connect to vulnerable audio devices and bypass intended permission controls protecting sensitive protocol functionality and data. The issue has been described as a permission bypass that enables access to critical RACE protocol data through the BLE GATT service and can serve as an entry point for broader compromise when combined with related flaws in the same platform.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Bluetooth Low Energy authentication flaw that allows an unauthenticated attacker to connect to the earbuds.
An Airoha SoC vulnerability that, when chained with related flaws, could help attackers intercept Bluetooth connections and interact with a connected smartphone.
A vulnerability that, when chained with CVE-2025-20701 and CVE-2025-20702, could enable hijacking of the Bluetooth Hands-Free Profile to issue commands to a phone.
A vulnerability affecting the same Airoha Bluetooth component that can be chained with CVE-2025-20701 and CVE-2025-20702 to hijack the connection between a phone and a paired Bluetooth audio device and issue HFP commands to the phone.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.