← Audio
C

AirPods Pro 2

Notable issues
Apple · 🇺🇸 United States · WiFi
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: BCG-A2699
Chipset: Apple H2
App: com.apple.android.music
Manufacturer: Apple

⚠️ The bottom line

Apple says your AirPods Pro 2 are just headphones that respect your privacy. In reality, they contain always-on microphones that continuously analyse every sound around you — detecting when you speak, classifying background noise, and tracking your head movements. The earbuds process audio 48,000 times per second. This is not disclosed when you buy them or in prominent marketing. To use Spatial Audio, Apple scans the unique shape of your ears using your iPhone's face-scanning camera — creating a biometric map of your body. Apple says this data stays on your device, but the earbuds connect to Apple's metrics and health servers, and there is no way to independently verify the data isn't transmitted.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
2/4 MODERATE
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
1Critical
5High
4Medium
4Sources
Findings by concern
Spying 4/4 EXTREME 5 findings
⚠️ criticalpolicy claims vs firmware analysis
Apple says your AirPods Pro 2 are just headphones that respect your privacy. In reality, they contain always-on microphones that continuously analyse every sound around you — detecting when you speak, classifying background noise, and tracking your head movements. The earbuds process audio 48,000 times per second. This is not disclosed when you buy them or in prominent marketing.

What they claim: Apple privacy policy states audio processing occurs on-device: "Health app features use your data on your device." Apple marketing positions AirPods Pro 2 as simple wireless headphones with privacy-by-design.

What we found: Firmware analysis reveals dual beamforming microphones are continuously active for ANC, Adaptive Transparency (processing 48,000 times/second), and Conversation Awareness (on-device ML detecting human speech). The H2 chip continuously analyses ambient audio to classify sounds and detect speech onset. While processing may be on-device, the device is functionally an always-on audio surveillance sensor — a capability never disclosed in marketing materials or prominently in privacy policy. Firmware endpoints include metrics.apple.com and metrics.icloud.com, confirming telemetry transmission.

⚡ highpolicy claims vs firmware analysis
To use Spatial Audio, Apple scans the unique shape of your ears using your iPhone's face-scanning camera — creating a biometric map of your body. Apple says this data stays on your device, but the earbuds connect to Apple's metrics and health servers, and there is no way to independently verify the data isn't transmitted.

What they claim: Apple claims Personalised Spatial Audio ear geometry data is "processed on-device and not sent to Apple servers." Privacy policy emphasises on-device processing and data minimisation.

What we found: Personalised Spatial Audio requires a TrueDepth camera scan of the user's ear canal geometry — creating a biometric 3D map of a uniquely identifying body part. While Apple claims on-device processing, the firmware connects to health-evidence.apple.com, metrics.apple.com, and metrics.icloud.com. There is no independent verification that ear geometry biometrics are never transmitted. The FCC filing (BCG-A2699) certifies 5GHz UNII band capability (5180-5240 MHz, 5745-5825 MHz) in addition to Bluetooth — raising questions about what data requires Wi-Fi-class bandwidth from earbuds marketed as Bluetooth devices.

⚡ highfirmware analysis vs regulatory findings
Your AirPods were approved by the FCC as simple wireless earbuds, but Apple later turned them into medical hearing aids that collect sensitive data about your hearing loss. This medical capability was added via software update without any new regulatory review of the privacy implications of collecting clinical health data.

What they claim: AirPods Pro 2 marketed as consumer headphones. FCC filing classifies them as "Wireless Earbuds" (BCG-A2699).

What we found: Since October 2024 (iOS 18.1), AirPods Pro 2 function as FDA-cleared over-the-counter hearing aids, processing clinical-grade audiogram data — sensitive medical biometric information revealing the specific frequencies and decibel levels at which a user's hearing degrades. This health data is stored in Apple Health and syncs to iCloud. The device was originally FCC-certified as simple "Wireless Earbuds" in September 2022, but now processes medical-grade health data that was never contemplated in the original regulatory filing. No updated FCC filing addresses the medical device capabilities.

⚡ highfirmware analysis vs policy claims
Apple says your data is secure, but security researchers found that anyone within Bluetooth range could hack into your AirPods and listen to your conversations. This happened twice (2023 and 2024). The combination of always-on Bluetooth and always-on microphones makes AirPods a tempting target for eavesdroppers.

What they claim: Apple's privacy policy emphasises security: "Apple is committed to the security of your data." AirPods are marketed as seamlessly secure within the Apple ecosystem.

What we found: Two high-severity Bluetooth authentication vulnerabilities have been found: CVE-2024-27867 and CVE-2023-27964. Both allow an attacker in Bluetooth range to spoof a previously paired device and gain access to the earbuds, potentially enabling eavesdropping on private conversations. CVE-2024-27867 required Apple's first-ever standalone security update for AirPods firmware. The always-on Bluetooth connectivity and always-active microphones create a persistent attack surface that Apple's security marketing does not acknowledge.

⚫ mediumpolicy claims vs firmware analysis
Apple describes Conversation Awareness as a helpful feature that pauses your music when you talk. What they don't emphasise is that this means your AirPods are always listening to detect when you start speaking — the same always-listening technology that caused privacy outrage when smart speakers did it.

What they claim: Conversation Awareness described by Apple as a convenience feature: "your AirPods will detect your speaking voice and recognize that you're trying to hold a conversation."

What we found: Conversation Awareness requires continuous real-time analysis of all audio input to distinguish human speech from background noise. The speech-detecting accelerometer and dual beamforming microphones work together with on-device ML on the H2 chip to continuously monitor for speech onset. This is functionally always-on speech detection — the same capability that drew widespread privacy criticism when Amazon and Google implemented it in smart speakers. Apple's framing as a simple "convenience feature" obscures the surveillance implications of a device that is literally always listening for you to start talking.

Data Sharing 2/4 MODERATE 2 findings
⚡ highapp permissions vs policy claims
Apple markets itself as the privacy champion, but their own Android app for AirPods includes Google tracking tools and requests access to your advertising ID, contacts, and camera. Apple uses the exact same tracking technology it publicly criticises other companies for using.

What they claim: Apple positions itself as the privacy-first alternative to Google/Android. Apple's privacy marketing states: "Privacy is a fundamental human right."

What we found: The Apple Music companion app (com.apple.android.music v5.1.2) on Android includes Google Firebase Analytics and Google CrashLytics trackers. It requests ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, AD_ID, and BIND_GET_INSTALL_REFERRER_SERVICE permissions — all advertising tracking permissions. The app also requests READ_CONTACTS, CAMERA, and BLUETOOTH access. Apple embeds the same Google advertising and analytics infrastructure it criticises competitors for using.

⚫ mediumfirmware analysis vs regulatory findings
Your AirPods case constantly broadcasts your location to Apple's network of over a billion devices. What Apple calls a "find my lost earbuds" feature has been used by stalkers to track people. Police can also ask Apple to tell them where your AirPods (and you) have been.

What they claim: AirPods Pro 2 marketed as personal audio devices. Find My integration described as a convenience feature for locating lost earbuds.

What we found: The MagSafe Charging Case contains a U1 Ultra Wideband chip that continuously broadcasts Bluetooth location beacons detectable by over 1 billion Apple devices in the Find My network. Law enforcement and security researchers have documented AirPods being used as stalking tools. Apple's own support page acknowledges this, stating "using AirTag to track people without consent is a crime." Apple can provide paired account details to law enforcement, effectively making AirPods a law-enforcement-accessible location tracker. The iFixit teardown revealed the lanyard insert may double as a U1 antenna — the tracking hardware is literally built into the structural design.

Security 2/4 MODERATE 1 finding
⚡ highpolicy claims vs regulatory findings
Apple says they don't sell your data and keep it encrypted. But Apple hands over your data to governments in 93% of cases when asked. They even accidentally gave user data to hackers who faked police requests. Your AirPods location data, connection logs, and usage patterns are all accessible to law enforcement.

What they claim: Apple privacy policy states: "Apple does not sell your personal data." Apple Health privacy page states data is "encrypted and inaccessible" when device is locked.

What we found: Regulatory evidence shows Apple complied with 93% of government data requests in H2 2020. Apple's law enforcement guidelines confirm Apple can provide: iCloud account data, iCloud backups (unless Advanced Data Protection is enabled — most users don't enable it), device registration, connection logs, and Find My location data. In 2022, Apple admitted providing user data to hackers who forged emergency law enforcement requests. AirPods generate Find My location beacons, Bluetooth connection logs, and usage telemetry — all accessible to law enforcement with valid process.

Honesty 4/4 EXTREME 2 findings
⚫ mediumapp permissions vs firmware analysis
The Apple Music app needs access to your camera, contacts, and can sync data in the background — far more than a music app should need. Combined with the AirPods' always-on sensors, this creates a pipeline for continuous data collection even when you're not actively using the app.

What they claim: Apple Music Android app requests 28 permissions for a music playback application.

What we found: The companion app requests CAMERA, READ_CONTACTS, BLUETOOTH, and MODIFY_AUDIO_SETTINGS beyond what music playback requires. The firmware reveals the H2 chip processes Conversation Awareness (speech detection), head tracking (gyroscope/accelerometer), and adaptive audio — all sensor data that flows through the paired device's app ecosystem. The app's FOREGROUND_SERVICE_DATA_SYNC permission enables background data synchronisation even when the app is not actively in use, allowing continuous telemetry collection from the connected AirPods.

⚫ mediumfirmware analysis vs policy claims
Apple talks about caring for the environment, but your AirPods Pro 2 are designed to be completely impossible to repair — scoring 0 out of 10 for repairability. When the battery dies in 2-3 years, you throw them away and buy new ones. You can't even replace the battery.

What they claim: Apple emphasises device repairability and environmental responsibility. Apple's Environment page promotes recycling programs and material recovery.

What we found: iFixit teardown gives AirPods Pro 2 a 0/10 repairability score — completely unrepairable, sealed construction with adhesive throughout. The lithium battery degrades over 2-3 years of daily use and cannot be replaced. Apple offers no battery replacement service for individual earbuds (only full-unit replacement at near-retail cost). This planned obsolescence contradicts Apple's environmental marketing and creates e-waste containing lithium batteries, rare earth metals, and the custom H2/U1 chips. The sealed design also prevents independent security auditing of the firmware.

Latest Risks & Threats
New developments that compound existing privacy concerns. 1 emerging risk.
RISK Camera AirPods — always-on visual surveillance in your ears ⚠️ Surveillance Announced 2026-05-07
Apple is deep into prototyping AirPods with built-in low-resolution cameras. Not for photos or video — for feeding visual context to Siri so it knows what you're looking at. Every glance, every shelf you browse, every document on your desk — processed by Apple Intelligence to make Siri 'helpful.' Meta Ray-Bans proved people film strangers with face cameras. Apple's version doesn't even show you what it sees.
Sources
What happened to real people
Documented incidents involving Apple products and user data.
PRISM participant since 2012. Apple dropped full iCloud E2EE plans (codenamed Plesio/KeyDrop) after FBI objections (Reuters 2020). Advanced Data Protection released 2022 as opt-in with deliberate friction. [source]
Apple handed over iCloud backups in 1,568 cases covering ~6,000 accounts. 90% compliance rate. Surveillance firm: 'If you did something bad, I bet I could find it on that backup.' [source]
Government requests for push notification metadata rose from 158 (H1 2023) to 277 (H1 2024). Push tokens can identify devices and link to accounts. [source]
What your data is worth to governments
Apple complied with 12,043 government data requests in H1 2024. That's +621% over 10 years. Apple has been a confirmed PRISM participant since 2012. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702).
Documented: PRISM participant since 2012. Apple dropped full iCloud E2EE plans (codenamed Plesio/KeyDrop) after FBI objections (Reuters 2020). Advanced Data Protection released 2022 as opt-in with deliberate friction.
Documented: Apple handed over iCloud backups in 1,568 cases covering ~6,000 accounts. 90% compliance rate. Surveillance firm: 'If you did something bad, I bet I could find it on that backup.'
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources