
Skullcandy Dime 3 wireless earbuds have a Bluetooth vulnerability that lets a nearby attacker pair with the device without putting it into pairing mode or getting the owner's approval.
Successful exploitation can let an attacker disrupt audio playback and potentially capture live microphone audio through the headset profile.
CERT/CC disclosed the issue in a bulletin after receiving a report from security researcher Jacob Nowak. The vulnerability note links the behavior to CVE-2025-20701, a previously disclosed flaw in Airoha Technology's Bluetooth audio SDK.
ERNW security researchers Dennis Heinze and Frieder Steinmetz originally identified CVE-2025-20701 and reported it to Airoha. Airoha published details of the high-severity flaw in August 2025, saying it affects its AB156x, AB157x, AB158x, and AB159x chipset families and allows Bluetooth BR/EDR devices to be paired outside their normal pairing mode. Apple fixed the flaw in Beats Studio earlier this year.
Skullcandy is a consumer audio company best known for wireless headphones, earbuds, and related accessories. CERT/CC confirmed that its Dime 3 earbuds (model S2DCW) are affected when running firmware version 1.0.0.28. The device's Bluetooth Plug and Play information identifies its chipset vendor as Airoha Technology.
According to CERT/CC, an attacker only needs to be within Bluetooth radio range and know or discover the earbuds' Bluetooth Classic address. No previous pairing, physical access, PIN, passkey, button press, or interaction with the charging case is required.
The earbuds accept a direct pairing request because they advertise a “NoInputNoOutput” I/O capability. The bonding process therefore finishes automatically, adding the attacker's system as a trusted device.
Once paired, the malicious device can reconnect whenever it is within range. CERT/CC found that an attacker can establish an A2DP audio connection and interrupt the owner's existing audio session. The earbuds play a “New device paired” notification, but only after the unauthorized pairing has already completed.
More seriously, CERT/CC says an attacker can access the Dime 3's Hands-Free/Headset profile and capture live microphone audio. Other Bluetooth Classic services exposed by the earbuds could potentially also become accessible after bonding.
Airoha addressed CVE-2025-20701 in patched software, and Skullcandy considers firmware version 1.0.0.30 to contain an effective fix. However, Skullcandy told CERT/CC that Dime 3 earbuds cannot receive firmware updates through its mobile application. No consumer-accessible method currently exists to upgrade affected units from firmware 1.0.0.28 to 1.0.0.30.
Owners of affected Dime 3 earbuds should therefore be cautious when using them in public or other environments where unknown devices may be within Bluetooth range. Treat unexpected pairing notifications as a possible compromise, and disconnect or stop using the earbuds for sensitive calls if you suspect unauthorized pairing.







Leave a Reply