
Bluetooth flaw exposes millions of premium headphones to spying
Cybersecurity firm ERNW has revealed that 29 devices using Airoha Bluetooth chips are vulnerable to attacks that could expose your personal data or let someone snoop on your conversations. The affected devices come from well-known brands, including Bose, Sony, JBL, Jabra and Marshall. They include headphones, earbuds, speakers and wireless microphones.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide —c free when you join my CYBERGUY.COM/NEWSLETTER
The Bluetooth flaws in question are built into Airoha chips commonly used in true wireless audio devices, as reported by BleepingComputer. Three flaws were disclosed, each allowing an attacker to gain some level of unauthorized access. The most serious flaw lets an attacker read or manipulate data by exploiting a custom protocol used by the chip. All three flaws have been assigned official CVE numbers and scored between medium and high severity.
To be clear, these are not casual attacks. They require close proximity and technical expertise. But when successful, the results are concerning. Researchers showed that they could extract call logs, contact lists and media being played. They could even force a phone to place a call without the user's knowledge. Once connected, they could listen in on any sound the phone picked up.
In one proof-of-concept, the researchers retrieved Bluetooth link keys from a headphone's memory. This allowed them to impersonate the device and hijack the connection to the phone. With that access, they could issue commands using the Bluetooth Hands-Free Profile, a feature available across most modern phones.
ERNW researchers have identified the following devices as vulnerable:
Keep in mind that this list may not include every product affected by these vulnerabilities. As more research emerges, the list could change. Furthermore, not every device faces all the same risks. For instance, at least one manufacturer seems to have already addressed CVE-2025-20700 and CVE-2025-20701. However, we do not know if this fix was intentional or accidental.
Because of these factors, getting a complete and accurate picture of which devices are truly secure remains a challenge. As a consumer, you should stay alert for updates and check with your device's manufacturer for the latest information.
Airoha has addressed the vulnerabilities in its software development kit (SDK) and released an updated version to device manufacturers in early June. These manufacturers are now responsible for building and distributing firmware updates to affected products. If you haven't seen an update yet, it should be arriving soon, though some may already be available.
However, there's a catch. According to a report by German outlet Heise, many of the most recent firmware updates for affected devices were released before Airoha provided its official fix. This means some products may still be running vulnerable code, despite appearing up to date.
To make matters more complicated, consumers typically aren't notified directly about these updates. Firmware patches for headphones and similar devices often install silently, or in some cases, may not be delivered at all. As a result, most users have no way of knowing whether their devices are secure or still exposed to risk.
We reached out to all 10 companies for a comment, but did not hear back before our deadline.
1. Regularly check for firmware updates: Visit the manufacturer's app or website to manually check for firmware updates, even if you haven't received a notification. Automatic updates aren't always reliable, especially for headphones and earbuds.
2. Turn off Bluetooth when not in use: Disabling Bluetooth when you're not actively using it reduces your exposure window and makes it harder for attackers to target your device.
3. Use devices in low-risk areas: Since these attacks require close proximity, avoid using Bluetooth audio devices in crowded or unfamiliar public places where someone nearby could exploit vulnerabilities.
4. Pair devices with trusted sources only: Avoid pairing your Bluetooth headphones with unfamiliar phones, computers or public terminals. Once paired, those devices can sometimes maintain a connection or reestablish one without your knowledge, increasing the risk of abuse if they're compromised.
5. Remove unused paired devices: Go into your Bluetooth settings and delete old or unfamiliar pairings. This helps prevent unauthorized reconnections from previously trusted devices that may now be compromised.
The real concern here isn't the Bluetooth flaw itself, but what happens when the software inside everyday devices fails quietly. Vulnerabilities like this aren't unusual, but the way they are handled often leaves users in the dark. As long as consumers can't see or control the software running inside their own headphones, problems like this will keep happening.
Should manufacturers be required to notify users directly when security flaws are discovered in their products? Let us know by writing us at Cyberguy.com/Contact
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER
Copyright 2025 CyberGuy.com. All rights reserved.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


TechCrunch
18 minutes ago
- TechCrunch
OpenAI and Google outdo the mathletes, but not each other
AI models from OpenAI and Google DeepMind achieved gold medal scores in the 2025 International Math Olympiad (IMO), one of the world's oldest and most challenging high school level math competitions, the companies independently announced in recent days. The result underscores just how fast AI systems are advancing, and yet, how evenly matched Google and OpenAI seem to be in the AI race. AI companies are competing fiercely for the public perception of behind ahead in the AI race: an intangible battle of 'vibes' that can have big implications for securing top AI talent. A lot of AI researchers come from backgrounds in competitive math, so benchmarks like IMO mean more than others. Last year, Google scored a silver medal at IMO using a 'formal' system, meaning it required humans to translate problems into a machine‑readable format. This year, both OpenAI and Google entered 'informal' systems into the competition, which were able to ingest questions and generate proof‑based answers in natural language. Both companies claim their AI models scored higher than most high school students and Google's AI model from last year, without requiring any human-machine translation. In interviews with TechCrunch, researchers behind OpenAI and Google's IMO efforts claimed that these gold medal performances represent breakthroughs around AI reasoning models in non-verifiable domains. While AI reasoning models tend to do well on questions with straightforward answers, such as math or coding tasks, these systems struggle on tasks with more ambiguous solutions, such as buying a great chair or helping with complex research. However, Google is raising questions around how OpenAI conducted and announced its gold medal IMO performance. After all, if you're going to enter AI models into a math contest for high schoolers, you might as well argue like teenagers. Shortly after OpenAI announced its feat on Saturday morning, Google DeepMind's CEO and researchers took to social media to slam OpenAI for announcing its gold‑medal prematurely — shortly after IMO announced which high schoolers had won the competition on Friday night — and for not having their model's test officially evaluated by IMO. Btw as an aside, we didn't announce on Friday because we respected the IMO Board's original request that all AI labs share their results only after the official results had been verified by independent experts & the students had rightly received the acclamation they deserved — Demis Hassabis (@demishassabis) July 21, 2025 Thang Luong, a Google DeepMind senior researcher and lead for the IMO project, told TechCrunch that Google waited to announce its IMO results to respect the students participating in the competition. Techcrunch event Tech and VC heavyweights join the Disrupt 2025 agenda Netflix, ElevenLabs, Wayve, Sequoia Capital — just a few of the heavy hitters joining the Disrupt 2025 agenda. They're here to deliver the insights that fuel startup growth and sharpen your edge. Don't miss the 20th anniversary of TechCrunch Disrupt, and a chance to learn from the top voices in tech — grab your ticket now and save up to $675 before prices rise. Tech and VC heavyweights join the Disrupt 2025 agenda Netflix, ElevenLabs, Wayve, Sequoia Capital — just a few of the heavy hitters joining the Disrupt 2025 agenda. They're here to deliver the insights that fuel startup growth and sharpen your edge. Don't miss the 20th anniversary of TechCrunch Disrupt, and a chance to learn from the top voices in tech — grab your ticket now and save up to $675 before prices rise. San Francisco | REGISTER NOW Luong said that Google has been working with IMO's organizers since last year in preparation for the test and wanted to have the IMO president's blessing and official grading before announcing its official results, which it did on Monday morning. 'The IMO organizers have their grading guideline,' Luong said. 'So any evaluation that's not based on that guideline could not make any claim about gold-medal level [performance].' Noam Brown, a senior OpenAI researcher who worked on the IMO model, told TechCrunch that IMO reached out to OpenAI a few months ago about participating in a formal math competition, but the ChatGPT-maker declined because it was working on natural language systems that it thought were more worth pursuing. Brown says OpenAI didn't know IMO was conducting an informal test with Google. OpenAI says it hired third-party evaluators — three former IMO medalists who understood the grading system — to grade its AI model's performance. After OpenAI learned of its gold medal score, Brown said the company reached out to IMO, which then told the company to wait to announce until after IMO's Friday night award ceremony. IMO did not respond to TechCrunch's request for comment. Google isn't necessarily wrong here — it did go through a more official, rigorous process to achieve its gold medal score — but the debate may miss the bigger picture: AI models from several leading AI labs are improving quickly. Countries from around the world sent their brightest students to compete at IMO this year, and just a few percent of them scored as well as OpenAI and Google's AI models did. While OpenAI used to have a significant lead over the industry, it certainly feels as though the race is more closely matched than any company would like to admit. OpenAI is expected to release GPT-5 in the coming months, and the company certainly hopes to give off the impression that it still leads the AI industry.
Yahoo
an hour ago
- Yahoo
Over 99% of XRP holders are in profit
Over 99% of XRP holders are in profit originally appeared on TheStreet. Fresh on-chain data from on-chain analytical platform Glassnode shows that 99.6% of XRP's circulating supply is sitting in profit, meaning that hardly anyone wants to sell at a loss. This figure highlights the substantial price hikes XRP has undergone over the past weeks, rising to $3.64 at one point. XRP investor sentiment has also reached the verge of euphoria; the percentage of supply in profit is currently near an 18-month spike is occurring as both futures open interest and 24-hour trading volumes have rapidly increased simultaneously, suggesting that it is not just retail investors who are getting long, with the percentage of supply in profit at one of its highest levels since 2018 when the asset hit its all-time high at $3.84. Bitcoin trails behind XRP Bitcoin (BTC) is up nearly 70% at over $117,000, and its percentage of supply in profit is at almost 97%, just under that of XRP. Historically, Bitcoin has very high returns for holders, but the recent vertical move of XRP has now temporarily surpassed it in terms of raw holder gains. As Bitcoin adoption increases and holding cycles grow longer, profits are more distributed across price levels. The sharp XRP rally has led to the majority of its holders being in profit in an extremely short this means for the market Such outsized levels of profitability often indicate turning points. Though it evinces very bullish sentiment, it could also be suggestive of profit-taking pressure in the short term. However, with increasing interest in futures and a steady volume, the momentum could move forward—especially if regulatory clarity emerges from the yet-to-be-enacted CLARITY Act. Over 99% of XRP holders are in profit first appeared on TheStreet on Jul 21, 2025 This story was originally reported by TheStreet on Jul 21, 2025, where it first appeared. Sign in to access your portfolio
Yahoo
an hour ago
- Yahoo
Why SentinelOne (S) Stock Is Trading Up Today
What Happened? Shares of cyber security company SentinelOne (NYSE:S) jumped 9.4% in the afternoon session after reports from Israeli media outlets suggested the cybersecurity firm was in advanced talks to be acquired by industry giant Palo Alto Networks. The speculation, which emerged from Hebrew-language publications, fueled a surge in trading volume to nearly double the daily average. While both companies declined to comment on what they termed "rumors or speculation," the reports suggested a potential deal could value SentinelOne between $8 billion and $10 billion. After the initial pop the shares cooled down and closed the day at $19.80, up 9.9% from previous close. Is now the time to buy SentinelOne? Access our full analysis report here, it's free. What Is The Market Telling Us SentinelOne's shares are quite volatile and have had 19 moves greater than 5% over the last year. In that context, today's move indicates the market considers this news meaningful but not something that would fundamentally change its perception of the business. The previous big move we wrote about was 3 days ago when the stock gained 3% on the news that Rosenblatt Securities initiated coverage with a "Buy" rating and a $24 price target. The investment firm noted that the AI-driven cybersecurity leader was "significantly undervalued," trading at an estimated 40% discount compared to its peers. Rosenblatt's analysis pointed to the company's strong year-over-year revenue growth and its successful shift toward non-endpoint solutions, which accounted for half of new bookings. The firm also highlighted SentinelOne's improving free cash flow, suggesting a clear path to value creation. This new rating presented a "compelling opportunity" for investors with a long-term perspective who could look past short-term macroeconomic challenges. SentinelOne is down 10.4% since the beginning of the year, and at $20.22 per share, it is trading 29.5% below its 52-week high of $28.68 from December 2024. Investors who bought $1,000 worth of SentinelOne's shares at the IPO in June 2021 would now be looking at an investment worth $475.76. Here at StockStory, we certainly understand the potential of thematic investing. Diverse winners from Microsoft (MSFT) to Alphabet (GOOG), Coca-Cola (KO) to Monster Beverage (MNST) could all have been identified as promising growth stories with a megatrend driving the growth. So, in that spirit, we've identified a relatively under-the-radar profitable growth stock benefiting from the rise of AI, available to you FREE via this link. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data