CVE-2024-27867 is an authentication bypass vulnerability affecting Apple AirPods and Beats headphones, allowing an attacker within Bluetooth range to spoof a previously paired device and gain unauthorized access to the headphones during a connection request. This medium-severity vulnerability (CVSS 4.3) requires physical proximity (adjacent network) and low attack complexity, potentially leading to unauthorized access (confidentiality impact). While there is no known active exploitation, public exploit code, or KEV entry, the issue has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6a326CPE matchmatch criteria | cpe:2.3:o:apple:airpods_firmware:*:*:*:*:*:*:*:* | ||
< 6f8CPE matchmatch criteria | cpe:2.3:o:apple:powerbeats_firmware:*:*:*:*:*:*:*:* | ||
< 6f8CPE matchmatch criteria | cpe:2.3:o:apple:airpods_pro_firmware:*:*:*:*:*:*:*:* | ||
< 6f8CPE matchmatch criteria | cpe:2.3:o:apple:beats_fit_pro_firmware:*:*:*:*:*:*:*:* | ||
< 6f8CPE matchmatch criteria | cpe:2.3:o:apple:airpods_max_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.