Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

2026-06-19T07:24:14Z7b686d60bed3521bd9d5786dc101ff163fff7b752e7bf2ce2992b61106b1e77f
Airoha SDKBeats Studio BudsBluetooth audioCISA KEVFortinet FortiSandboxGoogle Vertex AI SDKHTTP/3Joomla JCEMicrosoft DefenderNGINXRoguePlanetmalware campaignsransomwareremote code executionsupply chain compromisevulnerability roundup

What happened

The Hacker News roundup highlights multiple high- and critical-severity vulnerabilities and active attacks across vendors. Notable issues include a Beats Studio Buds Bluetooth authorization flaw in the Airoha audio SDK (CVE-2025-20701, CVSS 8.8) that can enable pairing/eavesdropping; two critical NGINX Open Source RCEs including a HTTP/3 use-after-free (CVE-2026-42530, CVSS 9.2); a CISA-listed, actively exploited Joomla JCE flaw (CVE-2026-48907, CVSS 10.0); Microsoft’s RoguePlanet Defender elevation-of-privilege zero-day (CVE-2026-50656, CVSS 7.8) with a patch in development; and active Forti‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
7b686d60bed3521bd9d5786dc101ff163fff7b752e7bf2ce2992b61106b1e77f
Enrichment time
2026-06-19T07:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.