#VU93406 Improper Authorization in AirPods firmware and Beats firmware - CVE-2024-27867
Published: June 27, 2024
Vulnerability identifier: #VU93406
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-27867
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
AirPods firmware
Beats firmware
AirPods firmware
Beats firmware
Software vendor:
Apple Inc.
Apple Inc.
Description
The vulnerability allows an attacker to perform spoofing attack.
The vulnerability exists due to the way the headphones are seeking a connection request to one of your previously paired devices. An attacker with physical proximity to the device can spoof the intended source device and gain access to your headphones.
Remediation
Install updates from vendor's website.