AB156x, AB157x, AB158x, AB159x series vulnerability

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Published 4 Aug 2025Updated 8 Sep 20264 sources
CVSS 8.8

What happened

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected versions

AB156x, AB157x, AB158x, AB159x series: Airoha IoT SDK for BT audio v5.5.0 and earlier; Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.