Description
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In plain language
AI Worth attentionCVE-2025-20702 is a serious security flaw in certain Airoha Bluetooth audio SDK-based devices that could allow remote attackers to gain higher privileges over Bluetooth-related RACE communications; if your business uses affected Airoha AB156x/AB157x/AB158x/AB159x/AB1627 series products, you should act soon even though there’s no known public exploit.
What to do
- Check whether your Bluetooth audio products are based on Airoha AB156x/AB157x/AB158x/AB159x series or AB1627, and whether they use the affected Airoha Bluetooth audio SDK. 2) Ask your device/hardware vendor or IT team for the exact patch/firmware update that addresses CVE-2025-20702. 3) If you can’t patch immediately, limit exposure by restricting Bluetooth availability where possible and monitor for vendor security guidance.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Уязвимость в наушниках Apple Beats Studio позволяла подслушивать разговорыru-ru·Хакер (xakep.ru)· Patch Beats Studio Buds mobile
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphoneen·The Hacker News· PoC Beats Studio Buds auth-bypass
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversationsen-us·BleepingComputer· PoC Beats Studio Buds info-disclosure
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-20702 and every CVE in our database. Create a free account — no credit card required.
Create Free Account