Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

Lifestyle

Your Bluetooth earbuds have a hidden eavesdropping flaw—and big brands aren't immune

Your Bluetooth earbuds have a hidden eavesdropping flaw—and big brands aren't immune
Your Bluetooth earbuds have a hidden eavesdropping flaw—and big brands aren't immune

Bluetooth earbuds have an eavesdropping problem—Anyone can listen to your Bluetooth earbuds from 50 feet away.

Most people treat Bluetooth earbuds as a passive accessory, something that sits in your ears and plays audio. The security conversation around them, when it happens at all, tends to focus on whether someone can intercept your music or track your location. Many devices can be hacked, and your Bluetooth earbuds are no exception.

Anyone can connect to your earbuds without permission

Software flaws leave the door wide open

A ear wearing a Moto Buds Loop earbud.
A ear wearing a Moto Buds Loop earbud.

It's hard to say that any device is completely safe thanks to a few major security flaws. One is WhisperPair, and another is targeting a debugging protocol buried inside widely used audio chips. These are a big deal, and more people should be aware of them, because they can be as bad as hacking a phone. Hackers don’t even need AI to finish the job; they’re literally part of the Bluetooth devices.

A big part of the hardware problem traces back to chips made by Airoha Technology, a MediaTek subsidiary whose components power a wide range of popular earbuds. There were serious flaws baked directly into Airoha's firmware.

The root of the problem is the RACE protocol. This is a factory diagnostic tool that manufacturers routinely leave switched on in finished, consumer-ready products, with no real access controls or authentication in place. Anyone within close enough range can connect to the protocol over Bluetooth Classic or BLE and start issuing commands.

Person wearing SteelSeries Arctis Nova 3X Bluetooth headphones
Bertel King / How-To Geek

On top of that hardware problem sits the WhisperPair vulnerability in Google's Fast Pair service. Fast Pair was designed to make Bluetooth pairing as painless as possible, using BLE beacons to give you quick, one-tap connections. The idea is that a device should only accept new pairing requests when the user has deliberately put it into pairing mode, usually by holding down a physical button.

This check relies on software logic instead of any real cryptographic enforcement. What that means in practice is that a nearby attacker can force a bond with someone's earbuds while they're just sitting there listening to music—no phishing, no special tools, and no action from the victim.

Once in, the attacker has the same access as the legitimate owner. They can take over the audio stream, inject voice prompts to manipulate virtual assistants, access contact lists, or simply turn on the built-in microphones and listen to whatever conversations are happening nearby.

People can listen to your calls from fifty feet away

Your earbuds won't give you any warning

Person holding up the inside of the Beyerdynamic Blue BYRD ANC 2 earbud
Hannah Stryker / How-To Geek

If an attacker is within about 50 feet of you, they can force a connection to your wireless earbuds without you ever knowing it happened. The attack exploits weaknesses in the fast-pairing systems built into many earbuds. Under normal circumstances, earbuds should only accept a new pairing request when the user has manually put them into pairing mode.

That's the basic idea, anyway. In practice, the checks that are supposed to enforce that rule are either broken or missing entirely across a surprisingly wide range of consumer earbuds. So in reality, all an attacker needs is a laptop or even a cheap device like a Raspberry Pi. They scan for nearby Bluetooth signals, find a target, and send a pairing request.

The earbuds—which don't bother to check whether they're actually supposed to be pairing with anyone—just accept it. The whole thing takes seconds, and you'd never know you were hit. From there, things get worse.

SoundPEATS Space headphones displaying logo on the earcups
Jerome Thomas / How-To Geek

The person wearing them gets no notification, no sound, no indicator on their phone. The attacker can listen in on whatever conversation is happening nearby. If the victim happens to be on a call, the attacker can hijack it. They can pull up a contact list, redirect audio, or quietly open a line to a number they control while leaving the microphone live and pointing at the victim.

There's also a longer-term problem that can follow people around for weeks or months without them realizing it.

Most operating systems have alerts built in to warn you if an unknown tracker is following you around. The problem here is that the alert, when it eventually fires, points to the victim's own earbuds as the source. Most people see that and assume it's a glitch, dismiss it, and move on. The attacker keeps their view of the victim's location and their access to the microphone until the earbuds are fully factory reset.

Big brands have this problem, and updating your phone won't fix it

You have to update your earbuds to stay safe

The side of a JLab Epic Open Sport earbud.
Bertel King / How-To Geek

There is an idea that bad security is only a problem with cheap, no-name gadgets. That is completely false. You could have a Sony, JBL, or Beats and still become a victim. Most manufacturers don't build their Bluetooth hardware and software from the ground up. Instead, they buy chips from shared suppliers like Airoha Technology and use ready-made software kits to speed things along.

That's fine until one of those shared components has a flaw baked into it. At that point, the problem doesn't stay contained to one brand; it spreads across dozens of them at once. Since the problem lives in the device firmware itself and not in your phone, turning Bluetooth off or updating your phone does nothing to fix it.

The only real fix is a firmware update installed directly on the earbuds or headphones. For Sony, JBL, Marshall, Jabra, and similar brands, that means downloading the manufacturer's companion app first. From there, you can connect your earbuds, go into the settings, and check for updates. It sounds obvious, but many people install that app once when they first get the headphones and never touch it again, which means their devices have been sitting exposed ever since.

If you're on the Beats Studio Buds specifically, the process works a little differently since Apple handles it automatically. The fix is included in Beats Firmware Update 1B211, and there's no button to push because it just rolls out in the background on its own.

To make sure it's actually landed, put the earbuds in the case, close the lid, and keep them near your paired iPhone, iPad, or Mac with enough battery on both ends.

To confirm the update went through, go into your phone's Bluetooth settings, tap the little info icon next to the Beats Studio Buds, and check that the firmware version says 1B211. If it shows something older, just leave the earbuds nearby and give it more time.

Check to see if you are vulnerable

The uncomfortable part of all this isn't the vulnerability itself; it's that the fix depends entirely on manufacturers pushing firmware updates and users actually installing them. If you own a model that can be fixed this way, checking for a firmware update takes about two minutes. It won't close every gap in Bluetooth security, but it keeps you safe.

Read full story on HowToGeek

Related News

More stories you might be interested in.

Top