PT-2025-27362 · Airoha · Airoha Bluetooth Chips

Dennis Heinze

+2

·

Published

2025-06-29

·

Updated

2026-02-04

·

CVE-2025-20700

CVSS v3.1
8.8
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airoha Bluetooth audio SDK versions prior to August 4, 2025
Description The Airoha Bluetooth audio SDK contains a permission bypass that allows access to critical data of the RACE protocol through the Bluetooth LE GATT service. This can lead to remote escalation of privilege without requiring additional execution privileges or user interaction. Reports indicate that attackers within Bluetooth range can hijack connections, make calls, and eavesdrop through a device's microphone. The vulnerability affects 29 audio devices from brands including Bose, Sony, and Jabra. The issue has been actively exploited.
Recommendations Update the Airoha Bluetooth audio SDK to a version released after August 4, 2025.

Fix

LPE

RCE

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-01011
CVE-2025-20700

Affected Products

Airoha Bluetooth Chips