CVE-2024-27867
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.
Published:Jun 26, 2024
Last Modified:Apr 2, 2026
EPS:Jun 26, 2024
EPSS Score:0.00084
CVSS Score:3.3
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
Airpods
Apple
Airpods
Vendor
Apple
Product
Airpods Firmware
Apple
Airpods Firmware
Vendor
Apple
Product
Airpods Max
Apple
Airpods Max
Vendor
Apple
Product
Airpods Max Firmware
Apple
Airpods Max Firmware
Vendor
Apple
Product
Airpods Pro
Apple
Airpods Pro
Vendor
Apple
Product
Airpods Pro Firmware
Apple
Airpods Pro Firmware
Vendor
Apple
Product
Beats Fit Pro
Apple
Beats Fit Pro
Vendor
Apple
Product
Beats Fit Pro Firmware
Apple
Beats Fit Pro Firmware
Vendor
Apple
Product
Powerbeats
Apple
Powerbeats
Vendor
Apple
Product
Powerbeats Firmware
Apple
Powerbeats Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
