Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
CERT/CC warns Skullcandy Dime 3 earbuds accept silent Bluetooth pairings via CVE-2025-20701, letting nearby attackers hijack audio and microphone.
CERT/CC reports the Skullcandy Dime 3 (model S2DCW) running firmware 1.0.0.28 is affected by CVE-2025-20701, a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK. An attacker in close range can pair without user interaction, then hijack audio playback, access the headset profile, and capture live microphone audio. Skullcandy fixed the issue in firmware 1.0.0.30, but existing units have no consumer-accessible update path via the app. The flaw was discovered by ERNW researchers and affects earbud and headphone products from multiple vendors; Apple patched it for Beats Studio Buds in June.
- CVE-2025-20701 is a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK
- Close-range attackers can pair silently, hijack playback, and capture live microphone audio
- Fix shipped in firmware 1.0.0.30, but existing units cannot be updated by customers
- ERNW researchers found the flaw, which affects earbud products from multiple vendors
- Apple patched the same SDK flaw for Beats Studio Buds in June
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20701 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 8.8 | 9% | PoC | — | — |
Full article469 words · extracted from bleepingcomputer.com · click to collapse

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction.
Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) uses to handle wireless connectivity and communication between the earbuds and connected devices.
Although Skullcandy says that the security issue was fixed in firmware version 1.0.0.30, regular users have no method to update devices, neither manually nor through the Skullcandy application.
An attacker in close range of a vulnerable device can connect over Bluetooth without a pairing PIN, physical access to the earbuds case, or an approving pairing request.
The CVE-2025-20701 vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.
It is a high-severity missing-authentication problem that affects a broad range of earbud and headphone products from multiple vendors.
Airoha published SDK updates to address the issue on August 4, 2025, and earbud manufacturers subsequently adopted the fixes to plug the security risks.
Apple addressed the flaw for its Beats Studio Buds via a firmware update released this June.
The Skullcandy Dime 3 is a wireless Bluetooth earbud that is very popular with young users looking for affordable products with bass-heavy sound tuning and long-lasting battery.
After receiving a tip from researcher Jacob Nowak, CERT/CC found that CVE-2025-20701 impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.
After pairing, the attacker’s device becomes trusted and can automatically reconnect when nearby, enabling them to interrupt the owner’s connection, hijack audio playback, access the headset profile, and capture live microphone audio.
The target may hear a “new device paired” notification after the rogue pairing has taken place, but this is easy to miss or dismiss as a momentary connection loss followed by a reconnection.
Skullcandy pushed an update for CVE-2025-20701 in firmware version 1.0.0.30; however, CERT/CC notes that users who bought the earbuds with an earlier firmware release have no way to upgrade to a safe version.
“Existing units running the vulnerable firmware cannot currently be updated by customers through the app,” the advisory explains.
“As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30.”
BleepingComputer has been unable to contact Skullcandy about Dime 3 users’ inability to upgrade to a safe firmware version, as the company's chatbot does not handle press requests.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/