Owners ask us three things about Bluetooth: is the radiation harmful, can someone hack it, and should it be off when nobody's using it. They don't carry equal weight, and the one worth acting on is rarely the one people arrive worried about.
The radiation question
People ask us this, and fairly. Bluetooth runs at 2.4 GHz, the same band as a microwave oven — and as your Wi-Fi, which is why a room full of paired speakers can make 2.4 GHz congestion look like a network fault. The band sounds alarming until you look at the power. Class 2 radios, the common case in phones, earbuds, mice and keyboards, top out around 2.5 mW. The cellular radio in that same phone is built to transmit up to 120 to 200 mW, and does exactly that when the signal is poor. A Wi-Fi access point runs near 100 mW. A microwave oven pushes 700 to 1,200 watts into a sealed metal cavity. An earbud sits four to five orders of magnitude below the oven.
Sharing a band tells you nothing on its own. Two separate things decide whether radiation can damage tissue: how much energy each photon carries, which frequency sets, and how much total power arrives, which the transmitter sets. Bluetooth loses on both. At 2.4 GHz each photon carries about ten millionths of an electronvolt, roughly a millionth of the 10 eV it takes to knock an electron off a molecule. Ionization is a threshold effect, not a running total, so hours of exposure never add up to the X-ray mechanism people are picturing. The National Cancer Institute puts it plainly: the energy is too low to damage DNA.
The regulatory picture gets described wrongly even by people trying to be reassuring. Phones are SAR-tested against the US limit of 1.6 W/kg because their cellular radios can approach it. Most Bluetooth accessories are never tested at all — at a few milliwatts they fall below the FCC's exclusion threshold, which is the regulator's own way of saying the power is too low to be worth measuring. "Exempt because it can't get close" is a stronger statement than "tested and passed."
Then there's the study everyone cites. In May 2011 the WHO's cancer agency, IARC, classified radiofrequency fields as Group 2B, possibly carcinogenic, on limited evidence for glioma from pre-2004 handsets at about 30 minutes a day over ten years. Group 2B is a statement about how much evidence exists, not how large a risk is, and Bluetooth was never assessed. Worth noting what IARC actually recommended in that release: hands-free devices. That is, among other things, a description of a Bluetooth headset. Since then a WHO-commissioned review in 2024 found moderate-certainty evidence that phone use likely does not increase glioma risk, and US brain tumor incidence has stayed flat straight through universal phone adoption.
So no, we see no health reason to switch Bluetooth off. The honest phrasing is "no established risk, with a mechanism that makes one implausible," which is not the same sentence as "proven harmless," and we'd rather give you the real one. What we would actually flag about earbuds is hearing: damage starts around 85 dB, phones can drive earbuds past 110 dB, and both iOS and Android ship a volume limit almost nobody turns on.
The attack surface that's real
The reversal that matters in 2026 is that the protocol isn't the problem anymore, the products are. KNOB, BIAS and BLURtooth were answered years ago in the specification, and the fixes are in current Windows, macOS, iOS, Android and mainline Linux. CVE-2023-45866 still matters on old hardware: an attacker in range tricks a device into accepting an emulated Bluetooth keyboard with no pairing prompt, then types as the user. NVD rates it 6.3 Medium, well short of the "critical takeover" framing it picked up in the trade press. It was fixed in December 2023 for current systems, and never for Android 4.2.2 through 10.
The clearest illustration of the real problem is the Airoha chipset family, CVE-2025-20700, -20701 and -20702, which sits inside headsets and earbuds from a long list of mainstream audio brands. The flaw is a factory diagnostic protocol reachable over the air with no pairing and no authentication. An attacker within Bluetooth range can read and write the device's memory and extract the stored Bluetooth link key — the shared secret your phone and your headphones use to trust each other. With that key they can impersonate your headphones to your phone and drive its hands-free profile. ERNW's proof of concept places a call to a number the attacker controls, which turns the handset into a live microphone.
The bounds are real and worth stating. The attacker has to be within about thirty feet, and there is no version of this that works over the internet. If you happen to be listening at that moment your audio drops, but idle earbuds sitting in a case give no such tell. ERNW's own advice is that people who consider themselves high-risk targets — their examples are journalists, diplomats and politicians, and we would add anyone in a contested legal or personal situation — should use wired headphones. For everyone else, keep firmware current and prune the paired-device list, on the logic that every stale pairing is one more link key sitting somewhere waiting to be stolen.
What makes Airoha the story isn't the exploit, it's the supply chain behind it. A fix has to travel from the chipset vendor, to the headphone manufacturer, to a product that may have no update mechanism at all. Airoha handed manufacturers a patched development kit on June 4, 2025. Six months later most tested devices were still running pre-patch firmware, so on December 27, 2025 ERNW published the full write-up along with a working toolkit, meaning the capability no longer requires original research — just proximity and a device nobody updated. Apple shipped a Beats firmware fix in June 2026, a full year after the patched SDK, and from a vendor with an unusually good update pipeline. Plenty of affected products still haven't been fixed at all.
One correction while we're here: the wireless keyboard risk people worry about is mostly not Bluetooth. MouseJack targets proprietary 2.4 GHz USB dongles from up to 300 feet with about $15 of hardware, so a Bluetooth or wired keyboard genuinely beats a bargain dongle set. And plainly, every attack above needs a person within roughly thirty feet. But thirty feet is the suite next door in a shared Houston office off the Katy Freeway, and the truck parked beside yours at a job site with a paired phone in the cupholder. The exception that earns real attention is keystroke injection: on an unpatched or unmanaged laptop that is arbitrary command execution and a foothold like any other, which is what detection on the endpoint is for.
What the radio gives away when nobody's using it
A Bluetooth LE device that is merely powered on transmits advertising packets any nearby receiver can log. No pairing, no app, no consent step. This isn't a breach story, it's an ordinary commercial capability: Cisco Meraki access points ship with a BLE radio that lists nearby clients with manufacturer, signal strength and estimated location. Phones don't broadcast a permanent hardware address, but the protection is thinner than you would think — in May 2025 the SIG published Core 6.1, which randomizes the timing of address rotations because fixed intervals turned out to be predictable enough to correlate across changes. Core 6.1 is a specification, though, not the silicon already in your pocket.
There's a corollary here that runs against instinct, and it's the one piece of advice in this article we'd ask you not to skip. Don't turn Bluetooth off on the phone of anyone who might be followed. A Bluetooth item tracker has no GPS of its own; it shouts, and hundreds of millions of strangers' phones do the locating. Apple's personal safety documentation requires Bluetooth on, Location Services on, tracking notifications allowed and airplane mode off for unwanted-tracker alerts to work at all. Turning Bluetooth off silences the only automatic warning that somebody tagged your car. That covers drivers, staff going through a divorce, and anyone with a protective order.
One last thing worth knowing. On iPhone, the Control Center Bluetooth button does not turn the radio off. Apple documents that it disconnects accessories, and that Bluetooth comes back at 5 a.m. local time, on restart, or as soon as you connect an accessory from Settings. The actual switch is in Settings.
What to actually do
Open the app you've never opened
For every headset and pair of earbuds in the business, open the manufacturer's companion app and check for firmware. That is how these fixes ship, most people have never launched it once, and fixes for flaws disclosed in 2025 were still arriving in mid-2026. It is the single highest-value minute in this article.
Patch the things that have a patch pipeline
Phones, tablets and laptops are where nearly all of this actually lands, and every flaw above is closed on a supported, current operating system. The failure mode is almost never a missing patch — it's a shipped patch nobody installed, which is what managed patching across the fleet exists to prevent.
Inventory the peripherals and give the orphans a retirement date
NIST's Guide to Bluetooth Security asks for an inventory of every Bluetooth device and its address. Almost nobody has one. Do it once — earbuds, headsets, keyboards, scanners, speakers, door hardware — and ask two questions of each: does the vendor ship firmware, and how would a fix actually reach it? Anything with no update path isn't broken, but it has a fixed service life and deserves a date on the calendar. While you're in there, delete retired devices from the paired lists of everything they touched, since a bond is stored on both sides. It's the Canvas breach vendor-exposure exercise, run on hardware instead of SaaS.
Set the policy centrally instead of asking people to remember
The answer to "should we just ban Bluetooth" is no. You scope it. Microsoft publishes exactly this for Windows: block advertising, discoverable mode, pre-pairing and Swift Pair, enforce a minimum encryption key size, and allow-list only the profiles the business actually uses. That belongs in centrally managed endpoint configuration, pushed out through Apple device management or its Windows and Intune counterpart. One caveat that catches people: the Apple restriction requires a supervised, company-owned device, so you cannot lock down an employee's personal iPhone this way.
Decide which rooms and roles justify a hard off
On a warehouse laptop, a kiosk, a conference room PC, a server or a fixed-function tablet, the radio is pure attack surface with no upside. Turn it off there — not because the radio is dangerous, but because a listening radio is an unlocked door, and the cheapest door to close is the one nobody walks through. Just know what a blanket ban breaks: cross-device passkey sign-in, hearing aids, continuous glucose monitors and insulin pump links, and the hands-free calling that federal rules effectively require of commercial drivers.
The bottom line
Of the three questions owners ask us, the radiation one has the clearest answer, and it isn't the one worth acting on. The hacking question is real but proximity-bound and almost entirely closed on anything you keep patched. What actually survives scrutiny is the least dramatic of the three: a supply chain where the fix exists and never arrives, and a radio quietly announcing itself to anything listening. Both of those are inventory problems, and inventory problems are solvable.
If you're a Houston-area business and you'd like someone to go through what's paired to what, which peripherals still get firmware, and how to set this policy centrally instead of device by device, we're around. Call 281-407-1619 or contact us.
Sources
- Bluetooth range and transmit power — Bluetooth SIG
- Cell Phones and Cancer Risk — National Cancer Institute
- IARC classifies radiofrequency electromagnetic fields as possibly carcinogenic, Press Release 208 — IARC
- Cell Phones and Specific Absorption Rate — FCC
- Mobile phone use and brain tumour risk, a systematic review — Karipidis et al., Environment International
- CVE-2023-45866 detail and CVSS score — NIST National Vulnerability Database
- Bluetooth Headphone Jacking, full disclosure of the Airoha RACE vulnerabilities — ERNW
- ERNW White Paper 74, Airoha RACE — ERNW
- MouseJack, injecting keystrokes into wireless mice and keyboards — Bastille Research
- If Wi-Fi or Bluetooth turns on automatically — Apple Support
- Detect unwanted trackers — Apple Personal Safety Guide
- Guide to Bluetooth Security, SP 800-121 Revision 2 — NIST
- Policy CSP Bluetooth settings for Windows — Microsoft Learn