A severe security vulnerability in Skullcandy Dime 3 earbuds allows attackers to hijack audio and microphones without user consent. Worryingly, many users have no way to update their firmware to fix the flaw.
- Skullcandy Dime 3 (model S2DCW) suffers from CVE-2025-20701, allowing unauthorized Bluetooth pairing.
- Attackers can hijack audio playback and capture live microphone audio without a PIN or physical access.
- While a fix exists in firmware 1.0.0.30, users on version 1.0.0.28 cannot manually update.
The Carnegie Mellon University CERT Coordination Center (CERT/CC) has issued a high-severity warning regarding the Skullcandy Dime 3 wireless earbuds. The vulnerability, tracked as CVE-2025-20701, stems from a flaw in the Airoha Bluetooth Audio SDK, which manages the wireless communication between the earbuds and the host device.
The flaw is particularly dangerous because it allows an attacker within close range to pair with the earbuds without requiring a pairing PIN, physical access to the charging case, or any form of user approval. Once the connection is established, the attacker's device is marked as 'trusted,' allowing for automatic reconnection in the future.
Why This Matters
BozokMedia analysis shows that this is not merely a connectivity glitch but a profound privacy breach. By gaining unauthorized access, an attacker can interrupt the owner's music, hijack audio playback, and most alarmingly, access the headset profile to capture live audio from the device's microphone. This turns a popular consumer electronic device into a potential surveillance tool.
The inability for consumers to patch their own hardware creates a permanent window of vulnerability that attackers can exploit indefinitely.
The vulnerability was first identified by ERNW researchers and presented at the TROOPER cybersecurity conference. It appears that the Airoha SDK flaw affected various manufacturers. For instance, Apple successfully patched a similar issue in its Beats Studio Buds via a June firmware update. However, Skullcandy's implementation has left users in a precarious position.
While Skullcandy has released firmware version 1.0.0.30 to address the risk, CERT/CC reports that there is currently no consumer-accessible method to update devices running version 1.0.0.28. The official Skullcandy application does not provide a manual update path for these specific units, leaving a significant portion of the user base exposed.
| Feature | Vulnerable Version (1.0.0.28) | Patched Version (1.0.0.30) |
|---|---|---|
| Unauthorized Pairing | Possible (No PIN required) | Blocked |
| Mic Access | Attacker can eavesdrop | Secure |
| Update Method | No consumer path available | Pre-installed/Factory |
Frequently Asked Questions
Q1: How do I know if my Skullcandy Dime 3 is vulnerable?
If your earbuds are running firmware version 1.0.0.28 and you cannot find an update option in the Skullcandy app, your device is likely affected.
Q2: Can I fix this manually?
Currently, CERT/CC states there are no known consumer-accessible methods to upgrade from the vulnerable version to the safe version.