ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Skullcandy Dime 3 Bluetooth Flaw (CVE-2025-20701, VU#859658) Lets Nearby Attackers Hijack Audio and Microphone

mediumVulnerabilityimportance 35CVE-2025-20701
What's new: First merged summary for this story: CERT/CC disclosed VU#859658 covering the unauthenticated Bluetooth pairing issue on Skullcandy Dime 3 (model S2DCW) firmware 1.0.0.28, linked to CVE-2025-20701 in the Airoha Bluetooth audio SDK. Firmware 1.0.0.30 is reported as an effective fix, but no consumer-accessible update path exists because the earbuds cannot be updated via the Skullcandy app.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds (model S2DCW) on firmware 1.0.0.28 accept unauthenticated Bluetooth Classic pairing due to a flaw linked to CVE-2025-20701 in the Airoha Bluetooth audio SDK, letting nearby attackers hijack audio and…

Skullcandy Dime 3 wireless earbuds (model S2DCW) running firmware 1.0.0.28 accept Bluetooth Classic BR/EDR pairing requests from unknown devices without the owner activating pairing mode, a flaw linked to CVE-2025-20701 in Airoha Bluetooth audio SDK implementations and tracked as VU#859658 by CERT/CC. The NoInputNoOutput I/O capability configuration allows an attacker within Bluetooth range who knows the device address to bond without any PIN, passkey, user action, or consent. Once bonded, the attacker's device can reconnect automatically whenever it is in range, disrupt the owner's active A2DP audio session, and access the Hands-Free (HFP) or Headset (HSP) profiles to potentially capture live microphone audio. Firmware 1.0.0.30 reportedly addresses the issue, but Dime 3 earbuds do not support firmware updates through the Skullcandy mobile app, leaving affected users without a known consumer-accessible upgrade path.

  • Affected product: Skullcandy Dime 3 wireless earbuds, model S2DCW, firmware 1.0.0.28.
  • Tracked as CERT/CC vulnerability note VU#859658 and linked to CVE-2025-20701 in Airoha Bluetooth audio SDK implementations.
  • The flaw allows unauthorized Bluetooth Classic BR/EDR pairing without pairing mode, PIN, passkey, user consent, or user action, via the NoInputNoOutput I/O capability configuration.
  • Attackers need only Bluetooth range and the device address; once bonded, the attacker's device auto-reconnects whenever in range.
  • Attackers can hijack the owner's active A2DP audio session and access Hands-Free (HFP) or Headset (HSP) profiles to potentially capture live microphone audio.
  • Firmware 1.0.0.30 reportedly fixes the flaw, but Dime 3 earbuds cannot be updated through the Skullcandy mobile app, leaving affected users without a known upgrade path.

Coverage timeline

  1. · 6d ago
    GBHackers· 25
    Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

    CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing, letting nearby attackers hijack audio and microphone.

  2. · 6d ago
    Cyber Security News· 35
    Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone

    Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing via Airoha SDK flaw CVE-2025-20701, enabling audio hijack and microphone capture.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20701
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent.

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
8.89% PoC