CVE-2024-27867

June 26, 2024, 12:44 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

AirPods

  • Firmware Update 6A326
  • Firmware Update 6F8

Beats

  • Firmware Update 6F8

Source

product-security@apple.com

Tags

CVE-2024-27867 details

Published : June 26, 2024, 4:15 a.m.
Last Modified : June 26, 2024, 12:44 p.m.

Description

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
https://support.apple.com/en-us/HT214111 product-security@apple.com
https://support.apple.com/kb/HT214111 product-security@apple.com
This website uses the NVD API, but is not approved or certified by it.