Cybersecurity

Vulnerability in Skullcandy Dime 3 Earbuds Enables Bluetooth Connection Hijacking

CERT/CC warned of a high-severity vulnerability in Skullcandy Dime 3 earbuds running version 1.0.0.28 that allows a nearby device to pair without the user’s consent. Although a fix is available in version 1.0.0.30, owners of affected units cannot update them through the app or by any consumer-accessible method, according to the warning.

2026-09-09
3 min read
8 views
فريق تحرير certi.news
Vulnerability in Skullcandy Dime 3 Earbuds Enables Bluetooth Connection Hijacking

The CERT Coordination Center at Carnegie Mellon University (CERT/CC) warned of a high-severity vulnerability in Skullcandy Dime 3 wireless earbuds that allows a nearby Bluetooth device to pair without user interaction or entry of a pairing code. The issue affects units running firmware version 1.0.0.28.

The vulnerability is tracked as CVE-2025-20701 and is related to a lack of authentication in the Airoha Bluetooth Audio SDK used by the Dime 3 earbuds, model S2DCW, to handle wireless connectivity and communication with paired devices.

What can an attacker do?

According to information provided by CERT/CC, an attacker does not need a PIN, physical access to the earbuds’ case, or the owner’s approval of a pairing request. Once pairing succeeds, the attacker’s device becomes trusted and can reconnect automatically whenever it is near the earbuds.

This could allow the attacker to disrupt the owner’s connection, hijack audio playback, access the earbuds’ profile, and capture live audio from the microphone. The user may hear a notification indicating that a new device has paired, but the notification could easily be ignored or interpreted as a temporary connection drop followed by a new connection.

A fix is available, but the update is not available to users

Skullcandy says the issue was fixed in firmware version 1.0.0.30. However, CERT/CC explains that units sold with an earlier version currently do not allow their owners to move to the secure version, either manually or through the Skullcandy app.

The warning stated that, as of its publication, there was no consumer-accessible way to upgrade an existing unit from version 1.0.0.28 to 1.0.0.30. BleepingComputer was also unable to obtain comment from Skullcandy about the inability to update, as the company’s bot did not handle press requests.

Why does this matter?

The significance of the case lies in the fact that the flaw is not limited to the possibility of intercepting a temporary connection; successful pairing grants the attacking device trusted status, expanding what it can do afterward. The absence of a consumer update mechanism also means that releasing a fix is practically insufficient for owners of affected units.

ERNW researchers discovered the vulnerability and presented it at the TROOPER cybersecurity conference last year. The article says the issue affects a wide range of earbud and headphone products from multiple companies, after Airoha published updates to its SDK package on August 4, 2025. Apple addressed the flaw in Beats Studio Buds through a firmware update released in June, but that does not provide a solution for non-upgradable Skullcandy units.

The source does not identify any active exploitation against Dime 3 owners, nor does it explain a unit replacement mechanism or Skullcandy’s final position. Therefore, for customers who own version 1.0.0.28, the actual updateability of the solution remains the most important practical question in this case.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news