Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Skullcandy Dime 3 Bluetooth Flaw Exposes Users to Audio Hijacking and Eavesdropping
September 11, 2026
Claude AI Agents Automate Cyberattacks, Develop Zero-Days, Evade Detection
September 11, 2026
WordPress AI Scans Plugin Updates for Malware Before Release
September 11, 2026
Home/CyberSecurity News/Skullcandy Dime 3 Bluetooth Flaw Exposes Users to Audio Hijacking and Eavesdropping
CyberSecurity News

Skullcandy Dime 3 Bluetooth Flaw Exposes Users to Audio Hijacking and Eavesdropping

Key Takeaways A critical security flaw (CVE-2025-20701) in Skullcandy Dime 3 wireless earbuds allows unauthorized Bluetooth pairing. Attackers can hijack audio, play their own content, or potentially...

Jennifer sherman
Jennifer sherman
September 11, 2026 4 Min Read
3 0

Key Takeaways

  • A critical security flaw (CVE-2025-20701) in Skullcandy Dime 3 wireless earbuds allows unauthorized Bluetooth pairing.
  • Attackers can hijack audio, play their own content, or potentially eavesdrop using the earbuds’ microphone.
  • The vulnerability affects Skullcandy Dime 3 (model S2DCW) earbuds running firmware version 1.0.0.28.
  • While a patched firmware (1.0.0.30) exists, current Dime 3 models lack a user-accessible update mechanism.

Skullcandy Dime 3 Bluetooth Flaw Exposes Users

A significant security vulnerability has been identified in Skullcandy Dime 3 wireless earbuds, creating a pathway for nearby threat actors to gain unauthorized control over the devices. This flaw enables attackers to establish a Bluetooth connection without the owner’s explicit permission, potentially leading to audio hijacking and even surreptitious eavesdropping via the built-in microphone.

Table Of Content

  • Key Takeaways
  • Skullcandy Dime 3 Bluetooth Flaw Exposes Users
  • Technical Details of the Vulnerability
  • Potential for Audio Hijacking and Eavesdropping
  • No User-Accessible Patch Available
  • What You Should Do

Designated as Vulnerability Note VU#859658, the issue specifically impacts Skullcandy Dime 3 earbuds, model S2DCW, operating on firmware version 1.0.0.28. Public disclosure of this vulnerability occurred on September 8, 2026, linking it to CVE-2025-20701, which describes an authentication weakness within the Airoha Bluetooth audio software development kit.

Technical Details of the Vulnerability

The core of the vulnerability lies in an insecure implementation of Bluetooth Classic (BR/EDR) pairing. Typically, wireless audio devices require manual activation of a pairing mode by the user before a new device, such as a smartphone or laptop, can establish a connection. This process often involves pressing a physical button, confirming a digital prompt, or entering a PIN or passkey.

However, the affected Dime 3 earbuds deviate from this standard security protocol. They reportedly accept pairing requests from unknown Bluetooth devices even when the owner has not initiated pairing mode. This bypasses the usual authentication safeguards.

Exploiting this flaw does not necessitate physical access to the earbuds, their charging case, or any interaction with their controls. Furthermore, it doesn’t require a pre-existing pairing history, PIN, or passkey. An attacker merely needs to be within standard Bluetooth radio range and identify the target earbuds’ Bluetooth Classic address. With this information, they can send a direct pairing request to the device.

Due to the earbuds’ “NoInputNoOutput” Bluetooth I/O capability, the pairing and subsequent bonding process can finalize without any confirmation from the owner. Once an attacker’s device is successfully bonded, it becomes a trusted Bluetooth connection, allowing automatic reconnection whenever the device is within proximity. This creates a persistent security risk rather than a transient disruption.

Potential for Audio Hijacking and Eavesdropping

Upon successful bonding, an attacker can establish an Advanced Audio Distribution Profile (A2DP) connection, effectively seizing control of the earbuds’ audio session. This could interrupt the legitimate user’s connection to their primary device, enabling the attacker to stream their own audio content through the earbuds or prevent the owner from accessing their active audio stream.

The only indication a user might receive is an audible “New device paired” announcement. By the time this alert sounds, the unauthorized pairing has already completed, leaving the user no opportunity to reject the connection before the attacker’s device is trusted.

More critically, an attacker could also access the earbuds’ Hands-Free Profile (HFP) or Headset Profile (HSP). These Bluetooth profiles facilitate microphone functionality, potentially allowing the attacker to capture live audio from the victim’s immediate environment through the Dime 3’s microphone, raising significant privacy concerns.

The underlying flaw, CVE-2025-20701, has been traced back to implementations within the Airoha Bluetooth audio SDK. Airoha Technology Corp. is identified as the vendor through the Dime 3 Bluetooth Plug and Play modalias, which lists Bluetooth SIG company ID 0x0094.

No User-Accessible Patch Available

According to CERT/CC reports, a patched firmware version, 1.0.0.30, is reportedly available. However, Skullcandy has confirmed a critical limitation: Dime 3 earbuds do not support firmware updates through the Skullcandy application or any other known consumer-accessible method. This means existing owners with devices running the vulnerable firmware version 1.0.0.28 currently have no practical way to install the security fix.

What You Should Do

  • Limit Use in Public: Avoid using affected Skullcandy Dime 3 earbuds in public or semi-public spaces where unknown individuals could be within Bluetooth range.
  • Monitor Pairing Notifications: Remain vigilant for any unexpected “New device paired” audio announcements from your earbuds. If you hear one, immediately investigate your device’s Bluetooth settings.
  • Remove Unknown Devices: Regularly review the list of paired Bluetooth devices on your smartphone or computer. Promptly remove any unfamiliar or suspicious entries.
  • Consider Alternatives: Given the lack of a user-installable patch, users with significant privacy or security concerns may need to consider alternative earbuds that offer regular, user-accessible firmware updates.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Claude AI Agents Automate Cyberattacks, Develop Zero-Days, Evade Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
September 10, 2026
Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
September 10, 2026
Critical Check Point VPN Vulnerabilities Allow RCE Attacks
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us