PT-2025-27362 · Airoha · Airoha Bluetooth Chips

Dennis Heinze

+2

·

Published

2025-06-29

·

Updated

2025-08-04

·

CVE-2025-20700

CVSS v3.1
8.8
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Airoha Bluetooth audio SDK versions (affected versions not specified)

Airoha Bluetooth chips versions (affected versions not specified)

**Description:**

The Airoha Bluetooth audio SDK and chips contain a permission bypass that allows access to critical data of the RACE protocol through the Bluetooth LE GATT service. This can lead to remote escalation of privilege without requiring additional execution privileges or user interaction. Multiple reports indicate that devices from brands such as Bose, Sony, and JBL are affected. The vulnerability allows attackers within Bluetooth range to hijack connections, make calls, and eavesdrop through the device’s microphone. It has been reported as actively exploited.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

LPE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-20700

Affected Products

Airoha Bluetooth Chips