New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones
ID: 1c533343-725d-524e-85ee-bb7501d7d94c
STIX ID: report--1c533343-725d-524e-85ee-bb7501d7d94c
Feed Name: Cyber Press
### Executive summary Security researchers disclosed three critical vulnerabilities in Airoha-based Bluetooth audio devices that expose an unauthenticated RACE protocol over BLE/Classic/USB, allowing attackers within radio range to extract stored Bluetooth link keys, impersonate paired headphones, and gain access to smartphone features (voice assistant, calls, contacts, microphone). The flaws affect dozens of confirmed models from major vendors (Sony, JBL, Jabra, Bose, Marshall, Beyerdynamic) and potentially thousands of devices worldwide; Airoha released SDK patches in June 2025 but vendor firmware adoption is inconsistent, and researchers published a RACE Toolkit and full technical details after coordinated disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
