Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

by · BleepingComputer

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction.

Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) uses to handle wireless connectivity and communication between the earbuds and connected devices.

Although Skullcandy says that the security issue was fixed in firmware version 1.0.0.30, regular users have no method to update devices, neither manually nor through the Skullcandy application.

An attacker in close range of a vulnerable device can connect over Bluetooth without a pairing PIN, physical access to the earbuds case, or an approving pairing request.

The CVE-2025-20701 vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.

It is a high-severity missing-authentication problem that affects a broad range of earbud and headphone products from multiple vendors.

Airoha published SDK updates to address the issue on August 4, 2025, and earbud manufacturers subsequently adopted the fixes to plug the security risks.

Apple addressed the flaw for its Beats Studio Buds via a firmware update released this June.

The Skullcandy Dime 3 is a wireless Bluetooth earbud that is very popular with young users looking for affordable products with bass-heavy sound tuning and long-lasting battery.

After receiving a tip from researcher Jacob Nowak, CERT/CC found that CVE-2025-20701 impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.

After pairing, the attacker’s device becomes trusted and can automatically reconnect when nearby, enabling them to interrupt the owner’s connection, hijack audio playback, access the headset profile, and capture live microphone audio.

The target may hear a “new device paired” notification after the rogue pairing has taken place, but this is easy to miss or dismiss as a momentary connection loss followed by a reconnection.

Skullcandy pushed an update for CVE-2025-20701 in firmware version 1.0.0.30; however, CERT/CC notes that users who bought the earbuds with an earlier firmware release have no way to upgrade to a safe version.

“Existing units running the vulnerable firmware cannot currently be updated by customers through the app,” the advisory explains.

“As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30.”

BleepingComputer has been unable to contact Skullcandy about Dime 3 users’ inability to upgrade to a safe firmware version, as the company's chatbot does not handle press requests.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report