Skullcandy Dime 3 Bluetooth Flaw (CVE-2025-20701, VU#859658) Lets Nearby Attackers Hijack Audio and Microphone
CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds (model S2DCW) on firmware 1.0.0.28 accept unauthenticated Bluetooth Classic pairing due to a flaw linked to CVE-2025-20701 in the Airoha Bluetooth audio SDK, letting nearby attackers hijack audio and…
Skullcandy Dime 3 wireless earbuds (model S2DCW) running firmware 1.0.0.28 accept Bluetooth Classic BR/EDR pairing requests from unknown devices without the owner activating pairing mode, a flaw linked to CVE-2025-20701 in Airoha Bluetooth audio SDK implementations and tracked as VU#859658 by CERT/CC. The NoInputNoOutput I/O capability configuration allows an attacker within Bluetooth range who knows the device address to bond without any PIN, passkey, user action, or consent. Once bonded, the attacker's device can reconnect automatically whenever it is in range, disrupt the owner's active A2DP audio session, and access the Hands-Free (HFP) or Headset (HSP) profiles to potentially capture live microphone audio. Firmware 1.0.0.30 reportedly addresses the issue, but Dime 3 earbuds do not support firmware updates through the Skullcandy mobile app, leaving affected users without a known consumer-accessible upgrade path.
- Affected product: Skullcandy Dime 3 wireless earbuds, model S2DCW, firmware 1.0.0.28.
- Tracked as CERT/CC vulnerability note VU#859658 and linked to CVE-2025-20701 in Airoha Bluetooth audio SDK implementations.
- The flaw allows unauthorized Bluetooth Classic BR/EDR pairing without pairing mode, PIN, passkey, user consent, or user action, via the NoInputNoOutput I/O capability configuration.
- Attackers need only Bluetooth range and the device address; once bonded, the attacker's device auto-reconnects whenever in range.
- Attackers can hijack the owner's active A2DP audio session and access Hands-Free (HFP) or Headset (HSP) profiles to potentially capture live microphone audio.
- Firmware 1.0.0.30 reportedly fixes the flaw, but Dime 3 earbuds cannot be updated through the Skullcandy mobile app, leaving affected users without a known upgrade path.
Coverage timelineoldest first · each row is one article
- · 6d agoSkullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
GBHackers· 25
CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing, letting nearby attackers hijack audio and microphone.
- · 6d agoSkullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone
Cyber Security News· 35
Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing via Airoha SDK flaw CVE-2025-20701, enabling audio hijack and microphone capture.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20701 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 8.8 | 9% | PoC | — | — |