Skullcandy Dime 3 Wireless Earbuds Vulnerability Could Allow Bluetooth Hijacking and Unauthorized Eavesdropping

Views: 33 views

499/69 Friday, September 11, 2026

The CERT Coordination Center at Carnegie Mellon University (CERT/CC) has issued an advisory warning users of Skullcandy Dime 3 wireless earbuds about a cybersecurity risk after discovering that the earbuds accept Bluetooth pairing requests from unknown nearby devices without requiring user authentication. The issue directly affects earbuds running firmware version 1.0.0.28 and has been assessed as a high-severity vulnerability. It could allow threat actors to take control of the device or violate user privacy without the user immediately noticing.

The vulnerability, tracked as CVE-2025-20701, is caused by the lack of an authentication mechanism in the Airoha Bluetooth Audio SDK used by the earbuds to manage wireless connections. If an attacker is within Bluetooth range, they can bypass the normal requirement to enter a PIN or press a button on the earbuds to approve pairing. Once pairing succeeds, the attacker’s device becomes trusted and can reconnect automatically in the future. This could allow the attacker to interfere with audio signals, control audio playback, and access the microphone to eavesdrop on live conversations. Although users may hear an audio notification when a new device is paired, it may be overlooked or mistaken for a temporary connection issue. Similar vulnerabilities have previously been disclosed and affected earbuds from multiple brands, with other manufacturers gradually releasing updates to address the issue.

Although the manufacturer has acknowledged the problem and fixed the vulnerability in firmware version 1.0.0.30, the report states that there is currently no method for general users to update affected devices from vulnerable firmware version 1.0.0.28 to a secure version by themselves, whether through an application or other means. As an initial risk reduction measure, users should exercise caution when using the earbuds in public areas. If they hear an abnormal connection notification, they should immediately check the Bluetooth settings on their smartphone. If suspicious activity is found, users are advised to reset the earbuds to factory settings and closely monitor official announcements from the manufacturer for future software update guidance.

Source: https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/