A newly disclosed security vulnerability in the Skullcandy Dime 3 wireless earbuds could allow attackers to hijack audio playback and even eavesdrop through the mic—all without the owner’s knowledge or approval. The issue impacts units running firmware version 1.0.0.28 and involves a serious flaw in how the earbuds handle Bluetooth pairing.
How the Vulnerability Works
Classified as VU#859658, the flaw—linked to CVE-2025-20701—originates from an authentication weakness in the Airoha Bluetooth audio SDK. It causes the earbuds to accept pairing requests even when the user has not initiated pairing mode. This breaks fundamental Bluetooth security expectations, such as having to press a button, enter a PIN, respond to a prompt, or explicitly allow a connection.
The exploit leverages “Bluetooth Classic” (BR/EDR) and the “NoInputNoOutput” I/O capability. In this setup, pairing can complete without any user input or confirmation. An attacker merely needs to be within Bluetooth range and know or discover the earbuds’ Bluetooth address—no prior pairing or user interaction is required. Once paired, the attacker’s device becomes trusted, allowing ongoing access whenever it’s nearby.
Risks for Users
Once an unauthorized connection is established, the attacker can hijack the earbud’s audio channel via the A2DP profile. That means legitimate users could be abruptly disconnected, or the attacker could start streaming their own audio through the earbuds. Even more unsettling, access to profiles like Hands-Free or Headset might allow microphone access, enabling someone to listen to surrounding audio without consent.
The only indication a user gets is a voice prompt saying “New device paired,” which by that point arrives after the attacker has already gained access. There is no way to reject the connection beforehand.
Patch Status and What Users Can (or Can’t) Do
A fix is included in firmware version 1.0.0.30, though there’s a catch: the Dime 3 doesn’t support firmware updates via the Skullcandy app. That means most existing users on firmware 1.0.0.28 are stuck with unpatched devices, at least for now.
For safety, users are advised to avoid using these earbuds in environments where unknown people may be nearby, monitor for unexpected pairing alerts, and routinely check/remove any unfamiliar devices from their Bluetooth paired-device lists.
This isn’t the first time a vulnerability in Bluetooth audio SDKs has risked unauthorized access—SDK flaws often create sweeping exposure across multiple devices and product lines. This case highlights how assumptions about input/output capabilities or user presence aren’t enough to guarantee safety.
Why this matters:As wireless audio becomes ubiquitous and further integrated into daily life, flaws like this show just how exposed we are—especially when devices silently accept connections. Businesses and consumers alike need to demand stricter firmware update paths and more transparent security notices. Watch closely whether Skullcandy enables forced auto-updates or public tools to install the patch; until then, these earbuds remain a weak link in personal Bluetooth security.