Connect with us

Hi, what are you looking for?

News

New Bluetooth Headphone Vulnerability Could Let Hackers Hijack Smartphones — Sony, Bose, JBL, Marshall and More Affected

Find out if your Bluetooth earbuds or wireless headphones are vulnerable, and update your firmware just in case.

JBL Live Buds 3 Earbuds, Bose QuietComfort Earbuds, Marshall Major V and sony WH-CH720N Bluetooth Headphones Lifestyle

Security researchers have been warning for years that the expanding IoT attack surface isn’t driven by flagship smartphones or laptops, but by the secondary devices permanently paired to them. Baby monitors, smart TVs with cameras, streaming players, connected appliances—and now wireless headphones and earbuds—operate as trusted endpoints with persistent Bluetooth access and minimal user visibility. The latest disclosure brings that risk into sharp focus. Multiple critical vulnerabilities have been identified in Bluetooth System-on-Chips from Airoha Technology, a major silicon supplier whose SoCs are embedded in headphones and earbuds from SonyBoseJBLMarshall, and Jabra.

These chips do far more than maintain a Bluetooth connection. They run the software that controls how your headphones pair with your phone, manage audio processing, handle microphones for calls and voice assistants, and maintain the trusted relationship between the headset and your smartphone. In practical terms, the chip inside your headphones decides what the device can hear, what it can transmit, and which devices it trusts.

When security flaws are found at this level, attackers don’t need to break into your phone directly—they can exploit the headphones as a weak link, using them as a doorway to listen in or interact with the connected phone without the user ever realizing it.

Verified vulnerable devices include several widely owned, mainstream models, not just niche products. Most notably, multiple Sony WH and WF series headphones are affected—including the extremely popular WH-1000XM5 and WF-1000XM5, two of the best-selling noise-canceling headphones and earbuds on the market. Also on the list are Bose QuietComfort Earbuds, a staple for frequent travelers, along with JBL Live Buds 3, which sell in very high volumes through big-box and online retailers. 

Marshall models such as the MAJOR V and MINOR IV are affected as well, alongside additional products from BeyerdynamicJabra, and Teufel. In other words, this isn’t an edge-case problem limited to obscure gear—some of the most commonly used wireless headphones and earbuds are squarely in scope.

Here’s what you need to know about how so-called headphone jacking attacks actually work, why these newly disclosed vulnerabilities matter in the real world, and—most importantly—what practical steps you should take right now to reduce your risk. This isn’t about panic or paranoia; it’s about understanding that the devices sitting on your head are no longer dumb accessories, and treating them with the same level of caution you already (hopefully) apply to the phone in your pocket.

How the RACE Protocol Turns Bluetooth Headphones Into an Attack Vector

race-toolkit.py

Researchers at ERNW, a European cybersecurity consultancy known for dissecting wireless and embedded systems, uncovered a serious design flaw affecting a wide range of Bluetooth audio products built on chips from Airoha Technology. At the center of the issue is an internal protocol called RACE—short for Remote Access Control Engine—that was never intended to be exposed outside the factory or service bench. This is precisely the kind of vulnerability ERNW is known for finding: problems that slip through certification and testing, only to surface after products are already deployed at massive scale.

RACE exists to make life easier for manufacturers. It’s used for diagnostics, servicing, and firmware updates during production and repair. On affected devices, however, ERNW found that RACE is accessible over multiple interfaces, including Bluetooth Low Energy, Bluetooth Classic, and USB connections, without proper authentication. In plain terms, the same low-level control tools engineers use to build and fix headphones can be reached wirelessly by someone nearby. Once accessed, RACE allows reading from and writing to device memory—both flash storage and active RAM—effectively turning a pair of headphones or earbuds into a small, fully controllable computer rather than a passive audio accessory.

In June 2025, ERNW researchers Dennis Heinze and Frieder Steinmetz disclosed multiple critical Bluetooth vulnerabilities affecting dozens of popular wireless audio products. The exposure spanned headphones, true-wireless earbuds, microphones, and speakers using Airoha Bluetooth Systems-on-Chip. The most troubling aspect was how little effort an attacker needed to get started. As Heinze stated at the time, “Any vulnerable device can be compromised if the attacker is in Bluetooth range. That is the only precondition.”

If successfully exploited, the implications go well beyond a theoretical security bug. Attackers could read media data from audio devices, intercept microphone recordings, impersonate headphones to issue commands to a paired smartphone, and quietly eavesdrop on conversations. That combination pushes these vulnerabilities out of nuisance territory and into the realm of real-world risk—especially given how casually most people still treat the security of the devices sitting on their heads every day.

Airoha subsequently released an updated software development kit to hardware vendors to mitigate CVE-2025-20700CVE-2025-20701, and CVE-2025-20702, and firmware updates have slowly begun to appear. Since then, Heinze and Steinmetz have published an updated technical report detailing the attack methodology and released a dedicated tool that allows researchers—and consumers—to test whether specific devices remain vulnerable. Their work, also covered by Forbes, underscores that this is not a theoretical exercise but a live ecosystem problem that depends heavily on vendor follow-through.

Advertisement. Scroll to continue reading.

That’s where the warning lights really start flashing. Users of affected products must update firmware to be protected—but in many cases, updates either don’t exist or haven’t been clearly documented.

Partial List of Impacted Devices


  • Beyerdynamic Amiron 300
  • Bose QuietComfort Earbuds
  • EarisMax Bluetooth Auracast Sender
  • Jabra Elite 8 Active
  • JBL Endurance Race 2
  • JBL Live Buds 3
  • JLab Epic Air Sport ANC
  • Marshall ACTON III
  • Marshall MAJOR V
  • Marshall MINOR IV
  • Marshall MOTIF II
  • Marshall STANMORE III
  • Marshall WOBURN III
  • MoerLabs EchoBeatz
  • Sony Link Buds S
  • Sony ULT Wear
  • Sony WF-1000XM3
  • Sony WF-1000XM4
  • Sony WF-1000XM5
  • Sony WF-C500
  • Sony WF-C510-GFP
  • Sony WH-1000XM4
  • Sony WH-1000XM5
  • Sony WH-1000XM6
  • Sony WH-CH520
  • Sony WH-CH720N
  • Sony WH-XB910N
  • Sony WI-C100
  • Teufel Tatws2

A partial list of impacted devices (listed above as of December 27, 2025) has been released, and anyone using those products should check directly with the manufacturer for firmware or security updates. The scale of the issue remains unsettled. “Due to the sheer amount of devices that are potentially still affected,” Heinze warned, “there is no proper overview over the current status of fixes.”

As Heinze confirmed, “An update might not be available, or the vendor might not have released information about whether the vulnerabilities were addressed in an update,” with only products from BeyerdynamicJabra, and Marshall known to have received fixes so far.

The Bottom Line

For most people, the odds of someone actively targeting their Bluetooth headphones are low—but low risk doesn’t mean zero risk, especially in a world where nearly every object around us now talks to something else. Wireless headphones aren’t just speakers anymore; they’re always-on IoT devices with microphones, memory, and persistent trust relationships with our phones. That alone changes the conversation.

Some manufacturers deserve credit for taking this seriously, others far less so, and that uneven response is part of the problem. The reality is that our growing dependence on interconnected devices makes vulnerabilities like this inevitable. Is this the cybersecurity crisis of the year? Probably not.

Don’t overthink this. If your headphones or earbuds support firmware updates, install them—now. Then take five minutes to clean house in your phone’s Bluetooth settings and remove any old or unused pairings. Wireless headphones are no longer harmless accessories; they’re networked devices with microphones and persistent access to your phone. When the fix is this easy and the downside involves your conversations and your data, rolling the dice makes no sense.

For more information: https://static.ernw.de/whitepaper/ERNW_White_Paper_74_1.0.pdf

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Advertisement

New Products

2026 Hisense S6 Mobile TV in Living Room

New Products

Hisense’s S6 FollowMe highlights a fast-growing market for mobile, lifestyle TVs—joining Samsung Movingstyle and LG StanbyME as the category continues to expand.

Samsung Freestyle+ Portable Projector Lifestyle Samsung Freestyle+ Portable Projector Lifestyle

New Products

Samsung unveils the Freestyle+ ahead of CES 2026, adding AI features and higher brightness to its lifestyle projector—still best suited for dark rooms.

Fender Mix Wireless Headphones and Elie E6 / E12 portable Bluetooth speakers Fender Mix Wireless Headphones and Elie E6 / E12 portable Bluetooth speakers

New Products

Extremely Loud Infinitely Expressive?Fender Audio makes a bold statement with ELIE E6 and E12 portable Bluetooth speakers and modular MIX wireless headphones.

2026 LG Gallery TV Lifestyle 2026 LG Gallery TV Lifestyle

New Products

LG’s new Gallery TV takes aim at Samsung Frame, TCL NXTFRAME, and Hisense CanvasTV with MiniLED tech, Gallery+ art, and design-first appeal. Pricing TBD.

LG Xboom by will.i.am portable Bluetooth Speakers 2026 line-up LG Xboom by will.i.am portable Bluetooth Speakers 2026 line-up

New Products

LG expands its xboom by will.i.am lineup with the Rock, Mini, Blast, and Stage 501—bringing AI sound, rugged designs, and party-ready power to CES...

Pro-Ject Audio CD Box RS2 Tube Silver CD Player Pro-Ject Audio CD Box RS2 Tube Silver CD Player

CD Players

Pro-Ject’s CD Box RS2 Tube doubles down on Red Book CDs with a balanced tube stage—no SACD, no digital inputs, and a $2,300 price...

You May Also Like

New Products

Extremely Loud Infinitely Expressive?Fender Audio makes a bold statement with ELIE E6 and E12 portable Bluetooth speakers and modular MIX wireless headphones.

New Products

Looking for a space saving all-in-one turntable system with Bluetooth connectivity? The Andover-One E might be worth checking out.

Articles

Shopping for wireless noise cancelling over-ear headphones in 2025? Here are our picks for the best you can buy on any budget.

Articles

Our favorite wireless noise cancelling earbuds of 2025 include Bose, Sony, Technics and Bowers & Wilkins.

Articles

Our favorite true wireless earbuds of 2024 include two noise cancelling earphones from Bose and Sennheiser at different prices points.

Reviews

In-depth review of the Bowers & Wilkins true wireless noise cancelling earbuds covers everything you need to know.

New Products

Final's UX1000 budget wireless ANC headphones are only $65, while the step-up UX5000 add aptX Adaptive and LDAC for $250.

New Products

The British audio company just introduced two totally redesigned in-ear ANC TWS earphones that audiophiles are sure to get excited about.

Advertisement

ecoustics is a hi-fi and music magazine offering product reviews, podcasts, news and advice for aspiring audiophiles, home theater enthusiasts and headphone hipsters. Read more

Copyright © 1999-2024 ecoustics | Disclaimer: We may earn a commission when you buy through links on our site.



SVS Bluesound PSB Speakers NAD Cambridge Audio Q Acoustics Denon Marantz Focal Naim Audio RSL Speakers