Beats Studio Buds Bluetooth Microphone Vulnerability: Firmware 1B211 Fix
Apple says Beats Studio Buds could allow a nearby attacker to listen through the microphone while the earbuds were unpaired and seeking pairing requests. Firmware 1B211 is the official fix, but independent post-update verification is still pending.
Apple has confirmed a Bluetooth security vulnerability affecting Beats Studio Buds and released firmware 1B211 as the fix. The issue could allow an attacker within Bluetooth range to listen through the microphone of earbuds that were not yet paired and were actively seeking pairing requests.
Current status: resolved-pending-verification. Apple confirms the vulnerability and the intended firmware fix, but SoundPath Lab has not found an independent technical retest or two independent owner confirmations proving that firmware 1B211 eliminates the issue.
Issue record
| Issue ID | SPL-BEA-TWS-001 |
|---|---|
| Brand | Beats / Apple |
| Exact model | Beats Studio Buds |
| Issue | A nearby attacker may be able to listen through the earbuds’ microphone while the product is unpaired and actively seeking pairing requests. |
| Impact | Potential privacy loss and unauthorized microphone access within Bluetooth range. |
| Trigger conditions | The earbuds are not yet paired, are actively seeking pairing requests, and an attacker is within Bluetooth range. |
| Official identifier | CVE-2025-20701 |
| Evidence | E3 — official Apple security advisory |
| Public sources used | One authoritative manufacturer advisory. Apple credits two security researchers, but that attribution is not counted as a second independent public source. |
| Affected scope | Beats Studio Buds. Hardware revisions, regions, batches and the complete vulnerable pre-fix firmware range are not stated. |
| Fix version | Beats firmware 1B211 |
| Manufacturer fix date | 16 June 2026 |
| First observed by SoundPath Lab | 16 August 2026 |
| Last checked | 17 August 2026 |
| Lifecycle status | Supported by firmware update; retail lifecycle Unknown |
| Commercial relationship | None known |
What Apple confirmed
Apple says a nearby attacker could listen through the microphone of Beats Studio Buds that were not paired and were actively seeking pairing requests. The company identifies the issue as CVE-2025-20701 and credits Dennis Heinze and Frieder Steinmetz of ERNW GmbH. Apple says the underlying problem affected open-source code used by the software.
The advisory does not establish that every unit, region or historical firmware build was vulnerable. It also does not provide a measured exploitation rate or evidence that the issue was used against consumers in the wild.
Official firmware fix
Apple released Beats firmware 1B211 on 16 June 2026. Beats firmware updates are delivered automatically while the headphones are paired with and within Bluetooth range of an iPhone, iPad or Mac.
Owners can check the installed firmware version in the Bluetooth information screen on an iPhone, iPad or Mac. A device showing 1B211 has received Apple’s stated fix. A later firmware should not automatically be described as security-equivalent unless Apple’s release information confirms that the fix is retained.
What owners should do
- Pair the Beats Studio Buds with an iPhone, iPad or Mac and keep the earbuds within Bluetooth range so the automatic update can be delivered.
- Check the firmware version in the device’s Bluetooth information screen.
- Until 1B211 or a later confirmed security-fixed version is installed, avoid leaving the earbuds in an active pairing state in public or other untrusted environments.
- If the update does not arrive, follow Apple’s current Beats firmware support instructions rather than installing files from third-party download sites.
Facts, inference and unknowns
Confirmed facts: Apple identifies Beats Studio Buds as affected, describes the nearby microphone-listening impact, assigns CVE-2025-20701 and names firmware 1B211 as the security update released on 16 June 2026.
Reasonable inference: Beats Studio Buds running older firmware may remain exposed until the update is installed. Apple does not enumerate the full vulnerable firmware range, so SoundPath Lab does not convert this into a more precise version claim.
Unknown: exact hardware revisions, regional scope, real-world exploitation, attack frequency, an Android-only update path and independent post-update reproduction results.
Verification status
This record remains resolved-pending-verification, not resolved-verified. Apple’s advisory confirms the issue and intended fix, but the available public evidence does not include an independent technical retest or two independent owner confirmations showing that the microphone-access path can no longer be reproduced on firmware 1B211.
Source
Related: Product Issues & Limitations · Firmware & App Update Tracker · Truth & Risks
Revision history
- 16 August 2026: Initial record created from Apple’s official security advisory. Status set to resolved-pending-verification; exact pre-fix firmware range and independent retest remain Unknown.
- 17 August 2026: Rechecked Apple’s advisory and both SoundPath Lab public trackers. The advisory was unchanged, no independent post-fix retest was found, and no duplicate SoundPath Lab record existed.
Feature image: neutral editorial illustration created for SoundPath Lab. It is not an official Beats product image and contains no brand marks.
Continue the research
Move from this article to a verified product decision
Use descriptive links to move between product records, brand evidence, comparisons, setup or issue guidance, and compatible-system tools. Inclusion reflects subject relevance, not a score or endorsement; product facts, recommendation eligibility, and commercial links remain separate.
Product page
Verify the exact model
Brand center
Check the wider platform
Related comparison
Compare the system role
Setup, firmware & problems
Check behavior before buying
System Builder & compatibility