ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

Skullcandy Dime 3 Earbuds Exposed to Silent Bluetooth Hijacking via CVE-2025-20701

mediumVulnerabilityimportance 45CVE-2025-20701
What's new: First merged summary of this story. Three reports published 2026-09-09 through 2026-09-11 (BleepingComputer, GBHackers, Cyber Security News) consistently cover the initial CERT/CC disclosure; no factual disagreements or follow-up developments between them.
Merged summary · glm-5.3 · rewritten as coverage arrives

CERT/CC (VU#859658) warns that Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing (CVE-2025-20701, Airoha Bluetooth Audio SDK), letting nearby attackers hijack audio and capture live microphone audio; a fix exists in…

A CERT/CC vulnerability note (VU#859658) describes a high-severity missing-authentication flaw, CVE-2025-20701, in the Airoha Bluetooth Audio SDK affecting Skullcandy Dime 3 wireless earbuds (model S2DCW, firmware 1.0.0.28). Due to the NoInputNoOutput I/O capability in the Bluetooth Classic (BR/EDR) implementation, an attacker within Bluetooth range who knows the device address can bond without the owner activating pairing mode and without a PIN, passkey, or any user interaction. Once bonded, the attacker's device can automatically reconnect whenever in range, disrupt the owner's active session, hijack the A2DP audio stream, and access Hands-Free (HFP) or Headset (HSP) profiles to capture live microphone audio. The flaw was discovered by ERNW researchers and affects earbud and headphone products from multiple vendors; Apple patched the same SDK flaw for Beats Studio Buds in June. Skullcandy says firmware 1.0.0.30 addresses the issue, but Dime 3 earbuds do not support firmware updates through the Skullcandy mobile app, leaving existing users without a known consumer-accessible patch path. All three reports agree on these facts with no material discrepancies.

  • Vulnerability: CVE-2025-20701, a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK, tracked by CERT/CC as VU#859658
  • Affected product: Skullcandy Dime 3 earbuds, model S2DCW, firmware 1.0.0.28
  • Attack prerequisites: Bluetooth range and knowledge of the device address only — no pairing mode, PIN, passkey, or user interaction required due to NoInputNoOutput configuration
  • Impact: attacker can bond over Bluetooth Classic (BR/EDR), auto-reconnect when in range, hijack the A2DP audio session, and use HFP/HSP profiles to capture live microphone audio
  • Fix: firmware 1.0.0.30 addresses the flaw, but the earbuds cannot be updated via the Skullcandy mobile app, leaving affected units without a consumer-accessible update path
  • The flaw was discovered by ERNW researchers and affects earbud and headphone products from multiple vendors
  • Apple patched the same Airoha SDK flaw for Beats Studio Buds in June 2026 per BleepingComputer's report

Coverage timeline

  1. · 6d ago
    BleepingComputer· 45
    Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

    CERT/CC warns Skullcandy Dime 3 earbuds accept silent Bluetooth pairings via CVE-2025-20701, letting nearby attackers hijack audio and microphone.

  2. · 5d ago
    GBHackers· 25
    Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

    CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing, letting nearby attackers hijack audio and microphone.

  3. · 5d ago
    Cyber Security News· 35
    Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone

    Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing via Airoha SDK flaw CVE-2025-20701, enabling audio hijack and microphone capture.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20701
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent.

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
8.89% PoC