PT-2024-22092 · Apple · Beats +1
Jonas Dreßler
·
Published
2024-06-26
·
Updated
2025-08-04
·
CVE-2024-27867
4.3
Medium
Base vector | Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
**Name of the Vulnerable Software and Affected Versions:**
AirPods versions prior to 6A326
AirPods Pro (all models) versions prior to 6A326
AirPods Max versions prior to 6A326
Powerbeats Pro versions prior to 6A326
Beats Fit Pro versions prior to 6A326
Beats versions prior to 6F8
**Description:**
An authentication issue existed due to improper state management. This allowed an attacker within Bluetooth range to spoof a previously paired device and gain unauthorized access to the headphones, potentially enabling eavesdropping. The vulnerability, tracked as CVE-2024-27867, affects AirPods (2nd generation and later), AirPods Pro (all models), AirPods Max, Powerbeats Pro, and Beats Fit Pro.
**Recommendations:**
AirPods versions prior to 6A326: Update to firmware version 6A326.
AirPods Pro (all models) versions prior to 6A326: Update to firmware version 6A326.
AirPods Max versions prior to 6A326: Update to firmware version 6A326.
Powerbeats Pro versions prior to 6A326: Update to firmware version 6A326.
Beats Fit Pro versions prior to 6A326: Update to firmware version 6A326.
Beats versions prior to 6F8: Update to firmware version 6F8.
Fix
Improper Authentication
Weakness Enumeration
Related Identifiers
Affected Products
References · 24
- https://support.apple.com/kb/HT214111 · Vendor Advisory
- https://support.apple.com/en-us/HT214111 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-27867 · Security Note
- https://twitter.com/aeroladyny/status/1830752321959014455 · Twitter Post
- https://twitter.com/0xdea/status/1810666026381492712 · Twitter Post
- https://twitter.com/AITCinnovate/status/1811036919196704812 · Twitter Post
- https://twitter.com/marcbel19406167/status/1952193367225585723 · Twitter Post
- http://seclists.org/fulldisclosure/2024/Jul/2 · Note
- https://twitter.com/CloneSystemsInc/status/1951243704322125902 · Twitter Post
- https://twitter.com/Frank_qwerty/status/1951480403270705545 · Twitter Post
- https://twitter.com/onestepsecureit/status/1811507254698397924 · Twitter Post
- https://t.me/true_secator/5901 · Telegram Post
- https://twitter.com/grok/status/1951629191046434850 · Twitter Post
- https://t.me/cvenotify/84446 · Telegram Post
- https://t.me/cvenotify/103709 · Telegram Post