Skullcandy Dime 3 Bluetooth Flaw Exposes Users to Audio Hijacking and Eavesdropping
Key Takeaways A critical security flaw (CVE-2025-20701) in Skullcandy Dime 3 wireless earbuds allows unauthorized Bluetooth pairing. Attackers can hijack audio, play their own content, or potentially...
Key Takeaways
- A critical security flaw (CVE-2025-20701) in Skullcandy Dime 3 wireless earbuds allows unauthorized Bluetooth pairing.
- Attackers can hijack audio, play their own content, or potentially eavesdrop using the earbuds’ microphone.
- The vulnerability affects Skullcandy Dime 3 (model S2DCW) earbuds running firmware version 1.0.0.28.
- While a patched firmware (1.0.0.30) exists, current Dime 3 models lack a user-accessible update mechanism.
Skullcandy Dime 3 Bluetooth Flaw Exposes Users
A significant security vulnerability has been identified in Skullcandy Dime 3 wireless earbuds, creating a pathway for nearby threat actors to gain unauthorized control over the devices. This flaw enables attackers to establish a Bluetooth connection without the owner’s explicit permission, potentially leading to audio hijacking and even surreptitious eavesdropping via the built-in microphone.
Table Of Content
Designated as Vulnerability Note VU#859658, the issue specifically impacts Skullcandy Dime 3 earbuds, model S2DCW, operating on firmware version 1.0.0.28. Public disclosure of this vulnerability occurred on September 8, 2026, linking it to CVE-2025-20701, which describes an authentication weakness within the Airoha Bluetooth audio software development kit.
Technical Details of the Vulnerability
The core of the vulnerability lies in an insecure implementation of Bluetooth Classic (BR/EDR) pairing. Typically, wireless audio devices require manual activation of a pairing mode by the user before a new device, such as a smartphone or laptop, can establish a connection. This process often involves pressing a physical button, confirming a digital prompt, or entering a PIN or passkey.
However, the affected Dime 3 earbuds deviate from this standard security protocol. They reportedly accept pairing requests from unknown Bluetooth devices even when the owner has not initiated pairing mode. This bypasses the usual authentication safeguards.
Exploiting this flaw does not necessitate physical access to the earbuds, their charging case, or any interaction with their controls. Furthermore, it doesn’t require a pre-existing pairing history, PIN, or passkey. An attacker merely needs to be within standard Bluetooth radio range and identify the target earbuds’ Bluetooth Classic address. With this information, they can send a direct pairing request to the device.
Due to the earbuds’ “NoInputNoOutput” Bluetooth I/O capability, the pairing and subsequent bonding process can finalize without any confirmation from the owner. Once an attacker’s device is successfully bonded, it becomes a trusted Bluetooth connection, allowing automatic reconnection whenever the device is within proximity. This creates a persistent security risk rather than a transient disruption.
Potential for Audio Hijacking and Eavesdropping
Upon successful bonding, an attacker can establish an Advanced Audio Distribution Profile (A2DP) connection, effectively seizing control of the earbuds’ audio session. This could interrupt the legitimate user’s connection to their primary device, enabling the attacker to stream their own audio content through the earbuds or prevent the owner from accessing their active audio stream.
The only indication a user might receive is an audible “New device paired” announcement. By the time this alert sounds, the unauthorized pairing has already completed, leaving the user no opportunity to reject the connection before the attacker’s device is trusted.
More critically, an attacker could also access the earbuds’ Hands-Free Profile (HFP) or Headset Profile (HSP). These Bluetooth profiles facilitate microphone functionality, potentially allowing the attacker to capture live audio from the victim’s immediate environment through the Dime 3’s microphone, raising significant privacy concerns.
The underlying flaw, CVE-2025-20701, has been traced back to implementations within the Airoha Bluetooth audio SDK. Airoha Technology Corp. is identified as the vendor through the Dime 3 Bluetooth Plug and Play modalias, which lists Bluetooth SIG company ID 0x0094.
No User-Accessible Patch Available
According to CERT/CC reports, a patched firmware version, 1.0.0.30, is reportedly available. However, Skullcandy has confirmed a critical limitation: Dime 3 earbuds do not support firmware updates through the Skullcandy application or any other known consumer-accessible method. This means existing owners with devices running the vulnerable firmware version 1.0.0.28 currently have no practical way to install the security fix.
What You Should Do
- Limit Use in Public: Avoid using affected Skullcandy Dime 3 earbuds in public or semi-public spaces where unknown individuals could be within Bluetooth range.
- Monitor Pairing Notifications: Remain vigilant for any unexpected “New device paired” audio announcements from your earbuds. If you hear one, immediately investigate your device’s Bluetooth settings.
- Remove Unknown Devices: Regularly review the list of paired Bluetooth devices on your smartphone or computer. Promptly remove any unfamiliar or suspicious entries.
- Consider Alternatives: Given the lack of a user-installable patch, users with significant privacy or security concerns may need to consider alternative earbuds that offer regular, user-accessible firmware updates.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.