A critical security flaw discovered by German cybersecurity firm ERNW has turned popular Bluetooth earbuds and headphones into potential surveillance tools, allowing attackers within 10 metres to access device memory and potentially hijack connected smartphones.

The vulnerabilities, presented at the TROOPERS 2025 conference, affect Airoha Bluetooth chips found in millions of audio devices from major manufacturers, including Sony, JBL, Bose, Marshall, and Jabra.

The security flaws, designated as CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702, carry high severity scores between 8.8 and 9.6 on the CVSS scale.

According to ERNW’s technical analysis published on Insinuator.net, the vulnerabilities stem from issues in Airoha’s proprietary protocol that operates across both Bluetooth Low Energy and Classic modes, allowing hackers to access device memory without needing to pair or authenticate with the target device.

Researchers demonstrated that attackers could hijack Bluetooth connections, steal link keys, impersonate headsets, and even take control of connected smartphones.

In one particularly concerning demonstration, the team showed how attackers could trigger phone redials, access call logs on Android devices, and activate microphones remotely, raising serious surveillance concerns for users in sensitive environments.

The extensive list of affected devices includes popular models such as Sony’s WH-1000XM series headphones, JBL Live Buds 3, Bose QuietComfort Earbuds, Jabra Elite 8 Active, and multiple Marshall audio products.

Sony appears to have the largest number of affected models, with devices ranging from the WF-1000XM3 earbuds to the flagship WH-1000XM6 headphones included in the vulnerability list.

While Airoha issued a patched software development kit on June 4, no major manufacturers have rolled out firmware updates to consumers as of June 30.

The delay is attributed to the complex supply chain relationships between chip manufacturers, device makers, and the final brands that sell the products to consumers.

Security experts recommend that users regularly check manufacturer apps, like Sony Headphones Connect or JBL Headphones, for firmware updates, disable Bluetooth in public places or sensitive environments such as business meetings, and avoid using affected headsets for confidential conversations until manufacturers confirm that security patches have been applied.

The discovery underscores how trusted consumer accessories can become unexpected weak points in digital privacy and security.

With millions of affected devices currently in use worldwide, the vulnerability highlights the urgent need for manufacturers to prioritise security updates and establish more efficient patch distribution systems for consumer electronics.