All stories
highExploited VulnerabilitiesCVE-2025-20701

Nearby Attackers Can Spy via Microphone Due to Airoha Bluetooth SDK Flaws

Airoha Technology Corp. has disclosed three high-severity vulnerabilities in its Bluetooth audio SDK affecting the AB156x to AB159x series chipsets. These flaws allow attackers to pair devices without user consent, access critical data, and escalate privileges remotely. Immediate patching is advised for affected versions.

Summary

In a recent security bulletin, Airoha Technology Corp. revealed three vulnerabilities within its Bluetooth audio SDK that pose significant risks to users of the AB156x through AB159x series chipsets. The most concerning of these, CVE-2025-20701, has a CVSS score of 8.8 and allows attackers to pair Bluetooth devices without user consent, potentially leading to unauthorized access and privilege escalation. This vulnerability, along with two others identified by security researchers Dennis Heinze, Frieder Steinmetz, and Julian Suleder, underscores the critical need for swift patching.

What Happened

The vulnerabilities were discovered in the Airoha Bluetooth audio SDK, a component used in various chipsets manufactured by Airoha Technology Corp. CVE-2025-20701 allows attackers to pair Bluetooth devices without user consent, leading to potential unauthorized access and privilege escalation. This flaw is particularly alarming because it requires no additional execution privileges or user interaction for exploitation.

Technical Details

CVE-2025-20700 involves a missing GATT authentication for RACE services with critical data, allowing permission bypass through the Bluetooth LE GATT service. Similarly, CVE-2025-20702 exposes unauthorized access to the RACE protocol's critical capabilities. Both vulnerabilities share the same attack vector: remote escalation of privilege without user interaction or additional execution privileges.

Affected Products and Fixed Versions

The affected products include the AB156x, AB157x, AB158x, and AB159x series chipsets, as well as the AB1627 model. The vulnerabilities impact Airoha IoT SDK for BT audio versions 5.5.0 and earlier, along with Airoha AB1561x/AB1562x/AB1563x SDK versions 3.3.1 and earlier.

Exploitation Status

While the source materials do not explicitly state that these vulnerabilities have been exploited in the wild, their high CVSS scores and ease of exploitation without user interaction make them attractive targets for attackers. The lack of a CISA KEV status further emphasizes the urgency for device OEMs to apply patches promptly.

Indicators of Compromise

The source materials do not provide specific indicators of compromise (IOCs) for these vulnerabilities. However, organizations should monitor their systems for unusual Bluetooth pairing activities and unauthorized access attempts, especially on devices using the affected Airoha chipsets.

Detection Opportunities

Organizations can detect potential exploitation by monitoring for unexpected Bluetooth device pairings and checking logs for unauthorized access attempts to critical data or services. Implementing network segmentation and strict access controls can also mitigate the risk of exploitation.

Timeline

The vulnerabilities were disclosed in a 2025 security bulletin published on Airoha's website. Device OEMs were notified before publication, allowing them time to develop and distribute patches. The exact timeline for patch availability was not specified in the source materials.

Why This Matters for Defenders

For defenders, these vulnerabilities highlight the importance of promptly applying security updates and monitoring systems for signs of exploitation. Given the ease with which attackers can exploit these flaws without user interaction, organizations must prioritize patch management and enhance their detection capabilities to protect against potential attacks.

What Remains Unclear

The source materials do not specify whether these vulnerabilities have been actively exploited in the wild. Additionally, details on when patches will be available for all affected products are lacking. Organizations should remain vigilant and seek updates from Airoha Technology Corp. and device OEMs regarding patch availability.

Defender Guidance

Defenders should immediately assess their exposure to the affected Airoha chipsets and apply patches as soon as they become available. Monitoring systems for unusual Bluetooth pairing activities and unauthorized access attempts is crucial. Implementing network segmentation and strict access controls can further mitigate the risk of exploitation. Organizations are advised to stay informed about updates from Airoha Technology Corp. regarding these vulnerabilities.

Hashtags

airoha, bluetooth vulnerability, CVE-2025-20701, privilege escalation, security patch

Harith Dilshan - h4rithd.com

Sources

  1. https://thehackernews.com/2026/06/apple-patches-beats-studio-buds-flaw.html
  2. https://www.airoha.com/product-security-bulletin/2025
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -