
Bluetooth flaw exposes millions of premium headphones to spying
Cybersecurity firm ERNW has revealed that 29 devices using Airoha Bluetooth chips are vulnerable to attacks that could expose your personal data or let someone snoop on your conversations. The affected devices come from well-known brands, including Bose, Sony, JBL, Jabra and Marshall. They include headphones, earbuds, speakers and wireless microphones.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide —c free when you join my CYBERGUY.COM/NEWSLETTER
The Bluetooth flaws in question are built into Airoha chips commonly used in true wireless audio devices, as reported by BleepingComputer. Three flaws were disclosed, each allowing an attacker to gain some level of unauthorized access. The most serious flaw lets an attacker read or manipulate data by exploiting a custom protocol used by the chip. All three flaws have been assigned official CVE numbers and scored between medium and high severity.
To be clear, these are not casual attacks. They require close proximity and technical expertise. But when successful, the results are concerning. Researchers showed that they could extract call logs, contact lists and media being played. They could even force a phone to place a call without the user's knowledge. Once connected, they could listen in on any sound the phone picked up.
In one proof-of-concept, the researchers retrieved Bluetooth link keys from a headphone's memory. This allowed them to impersonate the device and hijack the connection to the phone. With that access, they could issue commands using the Bluetooth Hands-Free Profile, a feature available across most modern phones.
ERNW researchers have identified the following devices as vulnerable:
Keep in mind that this list may not include every product affected by these vulnerabilities. As more research emerges, the list could change. Furthermore, not every device faces all the same risks. For instance, at least one manufacturer seems to have already addressed CVE-2025-20700 and CVE-2025-20701. However, we do not know if this fix was intentional or accidental.
Because of these factors, getting a complete and accurate picture of which devices are truly secure remains a challenge. As a consumer, you should stay alert for updates and check with your device's manufacturer for the latest information.
Airoha has addressed the vulnerabilities in its software development kit (SDK) and released an updated version to device manufacturers in early June. These manufacturers are now responsible for building and distributing firmware updates to affected products. If you haven't seen an update yet, it should be arriving soon, though some may already be available.
However, there's a catch. According to a report by German outlet Heise, many of the most recent firmware updates for affected devices were released before Airoha provided its official fix. This means some products may still be running vulnerable code, despite appearing up to date.
To make matters more complicated, consumers typically aren't notified directly about these updates. Firmware patches for headphones and similar devices often install silently, or in some cases, may not be delivered at all. As a result, most users have no way of knowing whether their devices are secure or still exposed to risk.
We reached out to all 10 companies for a comment, but did not hear back before our deadline.
1. Regularly check for firmware updates: Visit the manufacturer's app or website to manually check for firmware updates, even if you haven't received a notification. Automatic updates aren't always reliable, especially for headphones and earbuds.
2. Turn off Bluetooth when not in use: Disabling Bluetooth when you're not actively using it reduces your exposure window and makes it harder for attackers to target your device.
3. Use devices in low-risk areas: Since these attacks require close proximity, avoid using Bluetooth audio devices in crowded or unfamiliar public places where someone nearby could exploit vulnerabilities.
4. Pair devices with trusted sources only: Avoid pairing your Bluetooth headphones with unfamiliar phones, computers or public terminals. Once paired, those devices can sometimes maintain a connection or reestablish one without your knowledge, increasing the risk of abuse if they're compromised.
5. Remove unused paired devices: Go into your Bluetooth settings and delete old or unfamiliar pairings. This helps prevent unauthorized reconnections from previously trusted devices that may now be compromised.
The real concern here isn't the Bluetooth flaw itself, but what happens when the software inside everyday devices fails quietly. Vulnerabilities like this aren't unusual, but the way they are handled often leaves users in the dark. As long as consumers can't see or control the software running inside their own headphones, problems like this will keep happening.
Should manufacturers be required to notify users directly when security flaws are discovered in their products? Let us know by writing us at Cyberguy.com/Contact
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER
Copyright 2025 CyberGuy.com. All rights reserved.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CNET
9 minutes ago
- CNET
CNET Survey: 64% of People Say 'No Thanks' to Foldable Smartphones
Foldables have been a staple of the smartphone release cycle for years now, with offerings from companies like Samsung, Motorola and Google. But despite the refreshingly unique form factor in a sea of mobile uniformity, the vast majority of consumers still aren't interested. According to a CNET survey, 64% of respondents say they aren't willing or interested in buying a foldable smartphone in the next year, while just 13% say they are. Another 20% aren't sure if they want a foldable, and only 3% say they already own one. Foldables began making a resurgence in smartphone form about six years ago, when Samsung released the first Galaxy Z Fold and Motorola brought back the iconic Razr. Other companies like Google, Honor, Oppo and Huawei have released their own foldable devices, from book-style iterations to clamshell ones. There's still one key player that hasn't entered the game yet: Apple, which has been rumored to be developing a foldable iPhone for several years now. Reports say it's working with Samsung Display to develop screens for that upcoming phone. It's possible that once Apple enters the foldables space, interest will grow across the board. "Apple's potential entry in the market later in 2026 could indeed help [with] legitimizing and democratizing the category," Thomas Husson, principal analyst at Forrester, told me earlier this month. A niche market Despite the amount of options, foldables remain a niche market. They make up under 5% of smartphone shipments, according to a report by TrendForce. But sales are expected to rise. An IDC report says foldable shipments will reach 45.7 million units worldwide by 2028, a significant increase over the 18.1 million units shipped in 2023. Still, adoption is relatively slow. "It's a pretty big commitment for the average user to switch something they depend on so much," Ryan Reith, group vice president for IDC's Worldwide Device Tracker, told me ahead of Samsung Unpacked in early July. "Nobody wants a trade-off, especially when you're going to make that big transition." Phones like the Motorola Razr tap into nostalgia, and also offer variations at multiple prices. James Martin/CNET That's why companies are fighting tooth and nail to make their phones sleeker, cheaper and more powerful -- to varying degrees. Samsung's latest Galaxy Z Fold 7 puts the emphasis on a slimmer build and better camera, while slapping on a $2,000 price tag that will likely only make it appeal to die-hard tech enthusiasts or people without strict budget constraints. Motorola, meanwhile, has focused on developing more budget-friendly versions of its Razr smartphones, so you don't have to break the bank to tap into that foldable nostalgia in 2025 and beyond. (Samsung also has a "more affordable" version of its Galaxy Z Flip 7 that starts at $900). Still, appealing to a wider consumer base can be challenging, especially when so many people have reservations. The barriers to buying a foldable Some of the biggest issues preventing people from buying a foldable smartphone are high prices (36%), durability concerns (31%), not understanding the advantages over a regular phone (31%) and a perceived lack of practicality (26%). Also, 15% of people say foldables are too bulky, 10% said their preferred brand doesn't make a foldable yet and 8% are concerned about subpar camera quality. Many of those perceptions could soon change, thanks to the release of phones like the Z Fold 7, which places an emphasis on thinness, durability and a higher-grade camera. But other factors like a high price can still be a hindrance. And if you've sworn allegiance to another brand like Apple, it's possible nothing will convince you to switch to a foldable until that specific company makes one. That's the power of brand allegiance. The resistance to buying a foldable phone is fairly consistent across age groups. Millennials are the most keen to venture into foldable territory, with 19% of respondents saying they'd be interested in buying one in the next year (nostalgia no doubt plays a role here). They're followed by 14% of Gen Zers who would be willing to make that purchase, 10% of Gen Xers and 8% of Boomers. So far, that doesn't appear to be stopping phone makers from putting their hat in the ring and seeing if they can convince shoppers to fold. Methodology CNET commissioned YouGov Plc. to conduct the survey. All figures, unless otherwise stated, are from YouGov Plc. Total sample size was 2,121 adults, of whom 2,064 do not own a foldable smartphone. Fieldwork was undertaken between July 1 and 3, 2025. The survey was carried out online. The figures have been weighted and are representative of all US adults (aged 18+).


TechCrunch
9 minutes ago
- TechCrunch
Three things veteran planetary health investors look for in a startup
Ask any founder or investor: fundraising is never easy. And in a market with this level of uncertainty, the difficulties are compounded. 'Everyone has to go through fundraising, and it's a relatively challenging market right now,' Kyle Teamey, managing partner at RA Capital Planetary Health, told TechCrunch. 'That's good for a bit of empathy.' Teamey and his colleague Brigid O'Brien, also a managing partner with the firm, know this as well as anyone. They just closed a $120 million fund, their first for RA Capital Planetary Health. In the two years the team was fundraising, the market changed course dramatically. When they started, the ink was barely dry on the Inflation Reduction Act, and global trade was humming along. All of that changed in the past six months. 'All of this is cyclical,' O'Brien said. 'Kyle and I have often talked about this, and thinking about our careers and the highs and lows of the market that we've gone through multiple times.' Both have seen their share of ups and downs in the market. O'Brien started out as an investor at In-Q-Tel and BPH, the mining giant. Teamey, for his part, was a founder in the first clean tech era over a decade ago before becoming an investor at In-Q-Tel and Breakthrough Energy Ventures. Over the years, the pair have developed a rubric that helps them decide where to place their fund's money. Techcrunch event Tech and VC heavyweights join the Disrupt 2025 agenda Netflix, ElevenLabs, Wayve, Sequoia Capital — just a few of the heavy hitters joining the Disrupt 2025 agenda. They're here to deliver the insights that fuel startup growth and sharpen your edge. Don't miss the 20th anniversary of TechCrunch Disrupt, and a chance to learn from the top voices in tech — grab your ticket now and save up to $675 before prices rise. Tech and VC heavyweights join the Disrupt 2025 agenda Netflix, ElevenLabs, Wayve, Sequoia Capital — just a few of the heavy hitters joining the Disrupt 2025 agenda. They're here to deliver the insights that fuel startup growth and sharpen your edge. Don't miss the 20th anniversary of TechCrunch Disrupt, and a chance to learn from the top voices in tech — grab your ticket now and save up to $675 before prices rise. San Francisco | REGISTER NOW 'We have three screening criteria,' O'Brien said. First on their list is time to market. How quickly can a prospective company begin generating revenue? 'We saw a lot of success in companies, even seed stage companies that were able to do that,' she said. 'We look for companies that can be in-market in less than five years.' Second, they look at product market fit. 'We really want to have some sense that they're building something that people actually want to buy,' Teamey said. 'A common mistake among entrepreneurs is the 'if you build it they will come' mentality.' Lastly, Teamey and O'Brien look for companies that use the money they have efficiently. 'How fast can you graduate from venture capital?' O'Brien said. For many investors, the answer to those questions is usually 'software,' though it doesn't always have to be. 'There's a lot of things that are different,' Teamey said, though he adds that one common misconception — that deep tech startups aren't capital efficient — doesn't add up. 'Capital efficiency can actually be somewhat analogous [to software], but the capital intensity is often very different,' he said. That's part of why the company will write first checks with figures in the hundreds of thousands all the way up to $10 million, with rounds ranging from seed to Series C. 'The name of the round doesn't really matter, right? What matters is, what's your time to market and does their return profile fit our strategy?' RA Capital Planetary Health has written checks to Koloma, which is prospecting for geologic hydrogen, and AM Batteries, which has developed a new lithium-ion battery manufacturing process that promises to slash costs dramatically. AI-enabled recycling startup Sortera also made the cut, as did solar power electronics company Optivolt and energy retailer Bia. It's a wide range of sectors, and the choices were informed by market maps the RA Capital Planetary Health team has been assembling over the last couple of years. The maps help the team 'understand what matters most in a market, what are those adoption barriers, and then what companies can overcome those adoption barriers,' O'Brien said. 'It also helps us inform what are the average time-to-markets.' That detail is top of mind for the team as they navigate the current downturn in the market. 'This won't be the first time or the last time there will be a cycle,' O'Brien said. 'It's not always going to be like rocket ships.' 'There's pluses and minuses of every part of the cycle,' Teamey added. 'If you can figure it out now, you're going to crush it as the markets get better.'


CNET
9 minutes ago
- CNET
How This AI Video Tool Works to Enhance Independence for Blind and Low-Vision Communities
Apps with accessibility considerations built in can open up more of the world to the blind and visually impaired. And tech companies using artificial intelligence are working to open more doors for these communities. I've been researching how humans who need visual assistance can get support for navigating life. Aira Explorer, a visual interpreting service designed to help individuals who are blind or have low vision, connects people with trained professionals who provide real-time visual information through a smartphone camera. What is Aira Explorer, and how does it use AI? Aira was founded in 2015 by Suman Kanuganti and Michael Hingson, who aimed to create a service that delivers instant access to visual information and empowers people with impairments to navigate the world more independently. While some support platforms are volunteer-run, Aira's selling point is its 24/7 care and support. In 2023, Aira introduced Access AI, its AI-powered feature integrated into the Aira Explorer app. It allows you to take or upload photos and receive instant detailed AI-generated responses. One key feature of the app is called Aira Verify, in which a human visual interpreter can confirm or clarify AI's responses. This can help when AI gets something wrong, though I think needing a human to double-check AI responses somewhat defeats the purpose of this kind of tool. But hopefully the technology will advance so that those checks aren't necessary. The AI features within Aira Explorer, including Aira Verify, are free regardless of subscription model, to ensure as many people can benefit from the tool as possible. Aira also has an ASL app designed for on-demand interpreting to support the deaf and hard of hearing communities, though it's not available everywhere yet. How to use Aira to get real-time assistance The Aira Explorer app is available on iOS and Android, so you'll need your phone handy. Create an account and select a subscription plan or continue with Aira's free trial. You'll also need to set up a profile and enter personal preferences and accessibility needs. Then, choose your preferred language and notification settings before getting started. At the bottom of the screen, look for the Access AI button, where you can upload photos or ask the AI tool questions you want answered. If you'd like to use Aira Verify, your responses will be sent to a human agent for verification. (Note: If you attempt to make a call while using either of these services, you'll be charged for the time. More on pricing below.) If you'd like to speak to a human, navigate to Connect to start a live video call with an Aira agent. Use your smartphone camera to share your surroundings with them, and the agent will guide you through tasks that come up in your environment. AI also assists here by analyzing the scene or objects in the screen to support the agent helping you. Once you're finished, you can end the call and review the session, or log back on to speak with someone again. With its 24/7 abilities, you can get help at any time -- just make sure the internet connection is stable to create a smooth interaction between both you and the agent. Should you use Aira Explorer? It's wonderful that Aira Explorer offers people 24/7 care and uses technology as a medium for this. Blending AI and human support while providing individuals with tools to navigate the world more independently can be a strategic lifeline. Aira / Screenshot by CNET But with technology, there are some watchouts, particularly data and privacy considerations. If you're in a space without great internet, or an emergency situation, then Aira shouldn't (and can't) be your first choice to turn to for support. You should also be mindful of sharing personal information during sessions. Another potential deterrent is the cost. The starting price is $26/mo for 20 minutes, which you could wind up using on your first (and possibly only) call. However, one customer noted that this pricing was a bargain in comparison to a weekday support worker. Many institutions and organizations partner with Aira to offer services to their members, so if the individual cost is too high, it's worth asking whether access is available through one of them. Price aside, Aira's on-demand assistance can be crucial for 24/7 support to anyone navigating unfamiliar environments, reading printed materials, identifying objects and accessing digital content. This gives me hope that AI can drive further advancements and prove that tech-for-good can genuinely support and care for others.