The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction.
Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) uses to handle wireless connectivity and communication between the earbuds and connected devices.
Although Skullcandy says that the security issue was fixed in firmware version 1.0.0.30, regular users have no method to update devices, neither manually nor through the Skullcandy application.
An attacker in close range of a vulnerable device can connect over Bluetooth without a pairing PIN, physical access to the earbuds case, or an approving pairing request.
The CVE-2025-20701 vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.
It is a high-severity missing-authentication problem that affects a broad range of earbud and headphone products from multiple vendors.
Airoha published SDK updates to address the issue on August 4, 2025, and earbud manufacturers subsequently adopted the fixes to plug the security risks.
Apple addressed the flaw for its Beats Studio Buds via a firmware update released this June.
The Skullcandy Dime 3 is a wireless Bluetooth earbud that is very popular with young users looking for affordable products with bass-heavy sound tuning and long-lasting battery.
After receiving a tip from researcher Jacob Nowak, CERT/CC found that CVE-2025-20701 impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.
... continue reading