Bluetooth Authentication Issue in AirPods by Apple
CVE-2023-27964
5.4MEDIUM
What is CVE-2023-27964?
An authentication vulnerability in Apple AirPods allows attackers within Bluetooth range to spoof the intended source device during connection requests. This can result in unauthorized access to the headphones when attempting to connect to previously paired devices. Apple has addressed this security concern through improved state management in AirPods Firmware Update 5E133.
Affected Version(s)
AirPods Firmware Update E < 5
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved