logo

New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones

ID: 1c533343-725d-524e-85ee-bb7501d7d94c

STIX ID: report--1c533343-725d-524e-85ee-bb7501d7d94c

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2025-12-29

Date Updated: 2026-04-19

Author: AnuPriya

...
...

### Executive summary Security researchers disclosed three critical vulnerabilities in Airoha-based Bluetooth audio devices that expose an unauthenticated RACE protocol over BLE/Classic/USB, allowing attackers within radio range to extract stored Bluetooth link keys, impersonate paired headphones, and gain access to smartphone features (voice assistant, calls, contacts, microphone). The flaws affect dozens of confirmed models from major vendors (Sony, JBL, Jabra, Bose, Marshall, Beyerdynamic) and potentially thousands of devices worldwide; Airoha released SDK patches in June 2025 but vendor firmware adoption is inconsistent, and researchers published a RACE Toolkit and full technical details after coordinated disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.