Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone
Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing via Airoha SDK flaw CVE-2025-20701, enabling audio hijack and microphone capture.
CERT/CC vulnerability note VU#859658 describes insecure Bluetooth Classic (BR/EDR) pairing on Skullcandy Dime 3 (model S2DCW) firmware 1.0.0.28, linked to CVE-2025-20701 in the Airoha Bluetooth audio SDK. The NoInputNoOutput I/O capability lets unknown nearby devices pair without pairing mode, PIN, passkey or user interaction, then bond and automatically reconnect. An attacker can hijack the A2DP audio session and access Hands-Free or Headset profiles to capture live microphone audio. Firmware 1.0.0.30 reportedly fixes the flaw, but the earbuds cannot be updated through the Skullcandy app, leaving current users without a consumer-accessible patch path.
- Unauthorized Bluetooth Classic pairing works without pairing mode, PIN, passkey or user consent.
- Bonded attacker device auto-reconnects and can hijack the A2DP audio session.
- Hands-Free/Headset profile access can expose live microphone audio to nearby attackers.
- Firmware 1.0.0.30 reportedly fixes the flaw, but units cannot update via the Skullcandy app.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20701 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 8.8 | 9% | PoC | — | — |
Full article567 words · extracted from cybersecuritynews.com · click to collapse
A security vulnerability in Skullcandy Dime 3 wireless earbuds could allow nearby attackers to pair with the device without the owner’s approval, hijack audio playback, and potentially capture live microphone audio.
Tracked as Vulnerability Note VU#859658, the issue affects Skullcandy Dime 3 earbuds (model S2DCW) running firmware version 1.0.0.28.
The flaw was publicly disclosed on September 8, 2026, and is linked to CVE-2025-20701, an authentication weakness in the Airoha Bluetooth audio software development kit.
The vulnerability stems from insecure Bluetooth Classic (BR/EDR) pairing behavior. Normally, wireless earbuds must be deliberately placed into pairing mode before a new phone, laptop, or other device can connect.
Skullcandy Dime 3 Bluetooth Flaw
Users may also be required to press a button, confirm a prompt, enter a PIN, or accept a passkey request. However, affected Dime 3 earbuds reportedly accept a pairing request from an unknown Bluetooth device even when the owner has not activated pairing mode.
The attack does not require physical access to the earbuds, their charging case, or their buttons. It also does not need a prior pairing relationship, PIN, passkey, or any interaction from the victim.
An attacker only needs to be within normal Bluetooth radio range and know or discover the target earbuds’ Bluetooth Classic address. They can then send a direct pairing request to the device.
Because the earbuds use a NoInputNoOutput Bluetooth I/O capability, the pairing and bonding process can complete without the owner confirming the connection.
Once the attacker’s device is bonded, it becomes a trusted Bluetooth device. This means it can automatically reconnect to the earbuds whenever it is nearby, creating an ongoing risk rather than a one-time disruption.
The attacker could establish an Advanced Audio Distribution Profile (A2DP) connection and take over the earbuds’ audio session. This could interrupt the legitimate user’s connection to their smartphone or computer, allowing the attacker to play audio through the earbuds or deny the owner access to their active audio stream.
The only warning the user reportedly receives is an audible “New device paired” announcement. By the time the user hears that message, the unauthorized pairing has already succeeded, and the user has no opportunity to reject it before the attacker is trusted.
More concerningly, an attacker may also access the earbuds’ Hands-Free Profile or Headset Profile. These Bluetooth profiles can expose microphone functionality, potentially allowing the attacker to capture live audio from the victim’s surroundings through the Dime 3 microphone.
The underlying flaw was previously identified as CVE-2025-20701 in Airoha Bluetooth audio SDK implementations. Airoha is identified through the Dime 3 Bluetooth Plug and Play modalias, which lists Airoha Technology Corp. under Bluetooth SIG company ID 0x0094.
According to CERT/CC reports, a patch is reportedly available in firmware version 1.0.0.30. However, Skullcandy confirmed that Dime 3 earbuds do not support firmware updates through the Skullcandy application.
As a result, customers with existing units running firmware 1.0.0.28 currently have no known consumer-accessible way to install the fixed firmware.
Users should avoid using affected earbuds in locations where unknown people may be within Bluetooth range, remain alert for unexpected pairing notifications, and remove unfamiliar Bluetooth devices from paired-device lists where possible.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/skullcandy-dime-3-bluetooth-flaw/