Tag: Apple Patches

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has patched a high-severity vulnerability in its Beats Studio Buds wireless earbuds that might allow neighboring hackers to listen in on users. The vulnerability, identified as CVE-2025-20701 (CVSS score: 8.8), relates to an instance of improper authorization affecting the Airoha Bluetooth audio SDK, which allows a Bluetooth audio device to be paired without user permission. If the vulnerability is successfully exploited, remote privilege escalation may result without the need for further execution privileges or user input. Beats Firmware Update 1B211 has fixed the problem. According to a warning issued by Apple this week, an attacker within Bluetooth range may be able to listen through the microphone of a device that is not yet linked and actively seeking pair requests rea...
Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update
News

Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update

To fix a security vulnerability in iOS and iPadOS that it said has been exploited in the wild, Apple distributed out-of-band security patches on Monday. The vulnerability, which has been given the CVE identifier CVE-2025-24200, has been defined as an authorization problem that could allow a malevolent actor to disable USB Restricted Mode on a locked device as part of a cyberphysical attack. This implies that in order to take advantage of the vulnerability, the attackers need to have physical access to the device. USB Restricted Mode, which was first introduced in iOS 11.4.1, stops an Apple iOS or iPadOS device from interacting with an accessory if it hasn't been unlocked and connected to one in the previous hour read more about Apple Patches Actively Exploited iOS Zero-Day CVE-2025-...