Apple shipped a firmware patch for Beats Studio Buds that closes a hole letting nearby strangers listen in through the earbuds' microphone.
Firmware 1B211 addresses a Bluetooth vulnerability that could allow an attacker within radio range to access the device's microphone. The exploitation window is narrow: the earbuds had to be unpaired and actively soliciting a pairing request. The flaw originated in open-source code, and Apple listed its own software among the affected projects alongside the Beats hardware — a detail suggesting the vulnerable code runs in more places than one pair of earbuds.
That shared-code origin is what makes this worth noting beyond the modest real-world risk. Open-source Bluetooth stack bugs have a track record of turning up across many vendors before anyone realizes the exposure is connected. The scenario here — an attacker drifting into Bluetooth range of earbuds mid-setup — is niche, but "unpaired and searching" is exactly the state earbuds sit in during first-time setup or after a factory reset.
Updating is passive: drop the Studio Buds on a charger near a paired iPhone, iPad, or Mac, and the firmware installs itself. Low friction, which is good, because most people have never once thought of their earbuds as an attack surface.