A critical Bluetooth pairing flaw in Skullcandy Dime 3 wireless earbuds could let nearby attackers silently pair with the device, disrupt legitimate audio sessions, and capture live microphone audio without user interaction.
The issue, tracked in CERT Coordination Center Vulnerability Note VU#859658, affects Skullcandy Dime 3 earbuds (model S2DCW) running firmware version 1.0.0.28.
Attackers only need to be within Bluetooth radio range of the targeted earbuds; they do not need prior pairing, physical access, a PIN, a passkey, or owner approval.
Skullcandy Dime 3 Bluetooth Flaw
According to CERT/CC, the earbuds accept Bluetooth Classic (BR/EDR) pairing requests from previously unpaired devices, even when they have not been explicitly placed into pairing mode.
Under normal circumstances, a Bluetooth audio device should require the owner to initiate pairing mode or confirm an incoming request.
However, affected Dime 3 units reportedly process a direct pairing request sent to their discovered Bluetooth address and automatically complete bonding.
The earbuds use a NoInputNoOutput Bluetooth I/O capability, meaning they do not support passkey entry or on-device confirmation. This behavior enables a malicious device to create a trusted Bluetooth bond before the legitimate owner can prevent the connection.
The vulnerability is associated with CVE-2025-20701, a previously disclosed issue in the Airoha Bluetooth audio SDK. The Bluetooth Plug and Play modalias for the affected earbuds identifies Airoha Technology Corp. as the chipset vendor and uses Bluetooth SIG company ID 0x0094.
Once an attacker pairs with the earbuds, their device can remain a trusted Bluetooth peer and automatically reconnect whenever it is within range.
This persistence raises the risk beyond a one-time interruption, particularly in environments where an attacker may repeatedly be physically close to the victim.
An attacker can establish an Advanced Audio Distribution Profile, or A2DP, connection to the earbuds. This can interrupt the owner’s legitimate connection to their smartphone, laptop, or other paired device and effectively hijack the active audio session.
CERT/CC said the user may only hear a “New device paired” voice notification after the unauthorized pairing has already completed. Because the notification occurs after bonding, it does not give the owner a practical opportunity to reject the pairing attempt.
The issue also affects the device’s Hands-Free Profile and Headset Profile functions. A nearby attacker who successfully pairs with the earbuds may access those services and capture live audio from the earbuds’ microphone, potentially exposing conversations, calls, or ambient sound.
Skullcandy has indicated that the patch for CVE-2025-20701 is included in firmware version 1.0.0.30. However, the company confirmed that Dime 3 earbuds do not support firmware upgrades through the Skullcandy mobile application.
As a result, customers using devices on vulnerable firmware version 1.0.0.28 currently have no known consumer-accessible method to install the fixed 1.0.0.30 release.
Until an update mechanism or replacement option is made available, users should be cautious when using the earbuds in public or shared spaces where an attacker could operate within Bluetooth range.
Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC