Improper authentication in AirPods firmware and Beats firmware - CVE-2023-27964

 

Improper authentication in AirPods firmware and Beats firmware - CVE-2023-27964

Published: April 3, 2025


Vulnerability identifier: #VU106920
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27964
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain unauthorized access to device.

The vulnerability exists due to incorrect authentication mechanism when headphones are seeking a connection request to one of previously paired devices. An attacker in Bluetooth range can spoof the intended source device and gain access to headphones.


Affected software

AirPods firmware
Beats firmware

How to mitigate CVE-2023-27964

Install updates from vendor's website.

AirPods firmware - update to 5E133
Beats firmware - update to 5B66

External References

Related Security Bulletins