Bluetooth Security Flaws Linked to Popular Wireless Headphones

Posted on 3rd January, 2026 by Jason Sexton
Bluetooth Security Flaws Linked to Popular Wireless Headphones

Newly disclosed Bluetooth vulnerabilities are raising questions about the security of popular wireless headphones.

The disclosure has sparked concern that a large number of devices could be exposed to silent attacks within normal Bluetooth range. The issue came to light following a technical disclosure scheduled for the Chaos Communication Congress (39C3) in late December last year. Researchers outlined three vulnerabilities, reported as CVE-2025-20700, CVE-2025-20701 and CVE-2025-20702, affecting certain Bluetooth audio devices.

At the centre of the disclosure is an internal debug protocol known as RACE, originally intended for factory testing and firmware updates. According to the researchers, this protocol remained active on some production devices and could be accessed over Bluetooth Low Energy and Bluetooth Classic without authentication, something that was never meant to happen outside the factory.

In practical terms, an attacker within Bluetooth range could connect to a vulnerable headset without any user interaction, extract Bluetooth link keys from device memory, and impersonate the headphones to a previously paired smartphone. That could open the door to unauthorised access to call handling, voice assistants and other headset level functions, all without triggering a new pairing prompt on the phone.

Several cybersecurity outlets have independently confirmed the existence of the vulnerabilities and their technical basis, verifying that the CVEs are legitimate and that affected firmware builds are in circulation. What remains less clear is how often these flaws are being exploited outside controlled research environments.

Researchers have identified a range of affected products from major consumer audio brands, including models sold by Sony, Bose, JBL, Marshall and Jabra. Importantly, the issue does not appear to stem from brand specific software, but from shared Bluetooth hardware supplied by Airoha, a chipset manufacturer whose components are widely used across the audio industry.

Reports suggest Airoha supplied fixes to OEM partners in early 2025, though patch adoption appears mixed. While some manufacturers have since released firmware updates, others have yet to publicly address the issue. Because updates are typically delivered via companion apps, patched firmware may not be reaching devices at scale. This is hardly surprising. How often do most people actually open their headphone app once everything is set up?

Not all claims circulating online have been independently verified. While researchers have demonstrated headset impersonation and unauthorised Bluetooth access in lab conditions, reports of widespread consumer exploitation or account takeovers remain unconfirmed at the time of writing. Any real world attacks would still require proximity and a fair degree of technical expertise.

Apple’s AirPods are not believed to be affected, as they use a different Bluetooth architecture. For owners potentially affected, the immediate advice is to ensure headphone firmware is up to date, remove unused Bluetooth pairings, and disable Bluetooth when it is not needed. Users operating in higher risk environments may also wish to consider wired headphones for added peace of mind.

The episode highlights how deeply headphones are now integrated into smartphones and digital assistants, and how security, once secondary to sound quality and convenience, has become a core design responsibility. We will update this story as further information becomes available.

Join the discussion

Gallery

Jason Sexton's avatar
Jason Sexton

Jason joined StereoNET in 2025 and now serves as ANZ Editor, bringing decades of experience in marketing, brand development, and specialist hi-fi retail. His listener-first approach delivers grounded insights that cut through the noise. Outside audio, he’s into cars, trail riding, 80s nostalgia, and guitar.

Posted in: Headphones | Technology | Industry

JOIN IN THE DISCUSSION

Want to share your opinion or get advice from other enthusiasts? Then head into the Message Forums where thousands of other enthusiasts are communicating on a daily basis.
CLICK HERE FOR FREE MEMBERSHIP

applause awards

Each time StereoNET reviews a product, it is considered for an Applause Award. Winning one marks it out as a design of great quality and distinction – a special product in its class, on the grounds of either performance, value for money, or usually both.

Applause Awards are personally issued by StereoNET’s global Editor-in-Chief, David Price – who has over three decades of experience reviewing hi-fi products at the highest level – after consulting with our senior editorial team. They are not automatically given with all reviews, nor can manufacturers purchase them.

The StereoNET editorial team includes some of the world’s most experienced and respected hi-fi journalists with a vast wealth of knowledge. Some have edited popular English language hi-fi magazines, and others have been senior contributors to famous audio journals stretching back to the late 1970s. And we also employ professional IT and home theatre specialists who work at the cutting edge of today’s technology.

We believe that no other online hi-fi and home cinema resource offers such expert knowledge, so when StereoNET gives an Applause Award, it is a trustworthy hallmark of quality. Receiving such an award is the prerequisite to becoming eligible for our annual Product of the Year awards, awarded only to the finest designs in their respective categories. Buyers of hi-fi, home cinema, and headphones can be sure that a StereoNET Applause Award winner is worthy of your most serious attention.

Licensing Information

00001978