Permission Bypass in Airoha Bluetooth Audio SDK
CVE-2025-20700
Key Information:
- Vendor
Airoha Technology Corp.
- Vendor
- CVE Published:
- 4 August 2025
Badges
What is CVE-2025-20700?
The Airoha Bluetooth audio SDK contains a vulnerability that enables a permission bypass, granting unauthorized access to sensitive data associated with the RACE protocol via Bluetooth LE GATT service. This flaw allows potential escalations in privilege without requiring additional execution privileges or user interaction, making it a significant risk for users relying on the affected SDK for secure Bluetooth communications.
Affected Version(s)
AB156x, AB157x, AB158x, AB159x series, AB1627 Airoha IoT SDK for BT audio v5.5.0 and earlier
AB156x, AB157x, AB158x, AB159x series, AB1627 Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
