Skip to content
Tech News
← Back to articles

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

read original get Anker Soundcore Life P3 Wireless Earbuds → more articles
Why This Matters

A widely used Airoha Bluetooth SDK flaw (CVE-2025-20701) lets attackers within range pair with Skullcandy Dime 3 earbuds without any user approval, potentially hijacking audio and capturing live microphone input. Although a fixed firmware exists, Skullcandy provides no way for consumers to install it, leaving popular budget earbuds permanently exposed. It highlights how third-party chipset SDKs create supply-chain risk across many audio brands.

Key Takeaways
Worth a Look

Anker Soundcore Life P3 Wireless Earbuds — If the Dime 3's unpatchable pairing flaw has you eyeing a replacement, the Soundcore Life P3 is a solid, widely available swap with active noise cancelling and a companion app that actually pushes firmware updates. It's an easy way to keep true-wireless convenience without being stuck on a version you can't update.

See Anker Soundcore Life P3 Wireless Earbuds on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction.

Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) uses to handle wireless connectivity and communication between the earbuds and connected devices.

Although Skullcandy says that the security issue was fixed in firmware version 1.0.0.30, regular users have no method to update devices, neither manually nor through the Skullcandy application.

An attacker in close range of a vulnerable device can connect over Bluetooth without a pairing PIN, physical access to the earbuds case, or an approving pairing request.

The CVE-2025-20701 vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.

It is a high-severity missing-authentication problem that affects a broad range of earbud and headphone products from multiple vendors.

Airoha published SDK updates to address the issue on August 4, 2025, and earbud manufacturers subsequently adopted the fixes to plug the security risks.

Apple addressed the flaw for its Beats Studio Buds via a firmware update released this June.

The Skullcandy Dime 3 is a wireless Bluetooth earbud that is very popular with young users looking for affordable products with bass-heavy sound tuning and long-lasting battery.

After receiving a tip from researcher Jacob Nowak, CERT/CC found that CVE-2025-20701 impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.

... continue reading