CVE-2024-27867
Summary
| CVE | CVE-2024-27867 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-06-26 04:15:11 UTC |
| Updated | 2026-04-02 19:17:35 UTC |
| Description | An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.000840000 probability, percentile 0.245280000 (date 2026-04-02)
Problem Types: CWE-287 | When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones | CWE-noinfo Not enough information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.3 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | ADP | DECLARED | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Apple | Airpods | - | All | All | All |
| Operating System | Apple | Airpods Firmware | All | All | All | All |
| Hardware | Apple | Airpods Max | - | All | All | All |
| Operating System | Apple | Airpods Max Firmware | All | All | All | All |
| Hardware | Apple | Airpods Pro | - | All | All | All |
| Operating System | Apple | Airpods Pro Firmware | All | All | All | All |
| Hardware | Apple | Beats Fit Pro | - | All | All | All |
| Operating System | Apple | Beats Fit Pro Firmware | All | All | All | All |
| Hardware | Apple | Powerbeats | - | All | All | All |
| Operating System | Apple | Powerbeats Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.apple.com/kb/HT214111 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| seclists.org/fulldisclosure/2024/Jul/2 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List |
| support.apple.com/en-us/HT214111 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| support.apple.com/en-us/120907 | [email protected] | support.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.