logo

New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone

ID: 4f0e9faa-db25-5c9b-a6b1-8138ee572eb0

STIX ID: report--4f0e9faa-db25-5c9b-a6b1-8138ee572eb0

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-29

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Security researchers disclosed multiple critical Airoha Bluetooth SoC vulnerabilities (CVE-2025-20700/20701/20702) that expose a factory RACE protocol over BLE, Bluetooth Classic, and USB, allowing unauthenticated access, arbitrary read/write, and RCE; a publicly released RACE Toolkit and PoC chaining these flaws can extract pairing Link Keys to impersonate headphones and fully compromise connected smartphones, enabling eavesdropping and account takeover across many popular headphone models.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.