CVE-2024-27867
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6a326 |
| Running on/with | Platform Versions |
|---|---|
Apple Airpods | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6f8 |
| Running on/with | Platform Versions |
|---|---|
Apple Powerbeats | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6f8 |
| Running on/with | Platform Versions |
|---|---|
Apple Airpods Pro | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6f8 |
| Running on/with | Platform Versions |
|---|---|
Apple Beats Fit Pro | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6f8 |
| Running on/with | Platform Versions |
|---|---|
Apple Airpods Max | All versions |
References (4)
Source: product-security@apple.com
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Timeline
No history available yet.