A security flaw affecting some Skullcandy Dime 3 wireless earbuds can allow a nearby attacker to pair with the device without approval, interfere with audio playback, and potentially access the built in microphones.
The issue affects Dime 3 earbuds running firmware version 1.0.0.28 and is tracked as CVE 2025 20701. The vulnerability comes from the Airoha Bluetooth Audio SDK used by the earbuds.
The underlying problem is missing authentication during Bluetooth pairing. According to the advisory, an attacker within Bluetooth range can send a connection request that the earbuds may accept automatically, without requiring a PIN, passkey, button press, or manual pairing mode.
Unauthorized pairing can happen without confirmation
The Dime 3 uses a Bluetooth profile described as NoInputNoOutput. That profile is designed for devices that do not have a keyboard, screen, or other input method for entering pairing credentials.
In this case, the implementation allows incoming Bluetooth Classic pairing requests to complete without meaningful confirmation from the owner.
| Detail | Information |
|---|---|
| Affected product | Skullcandy Dime 3 |
| Vulnerable firmware | 1.0.0.28 |
| Fixed firmware | 1.0.0.30 |
| Vulnerability | CVE 2025 20701 |
| Underlying software | Airoha Bluetooth Audio SDK |
| Attack range | Bluetooth radio range |
| User approval required | No |
| Possible impact | Audio disruption and microphone access |
| Update available to older units | No over the air update support |
Once a malicious device pairs successfully, it can be added to the earbuds' trusted device list.
That means it may reconnect automatically when it comes back within range.
Attackers could interrupt audio or use the microphone
After pairing, an attacker could use standard Bluetooth audio profiles to interfere with playback.
Through A2DP, a malicious device could stop an existing audio session or send its own audio to the earbuds.
The more serious risk involves the Hands Free and Headset profiles. These can provide access to the earbuds' built in microphones.
In that situation, the earbuds could potentially stream ambient audio to the attacker's device while the attacker remains within wireless range.
The attack does not require physical possession of the earbuds.
The warning can appear too late
The main indication of a new connection is reportedly a short sound or a spoken "New device paired" notification.
The problem is that the message appears only after the pairing process has already succeeded.
That gives the owner no opportunity to reject the connection before it is accepted.
In a quiet room, the alert may be noticeable. In a busy place such as an airport, cafe, or public transport, it could easily be missed.
Firmware 1.0.0.30 fixes the issue
Airoha has released fixes for the affected Bluetooth SDK, and Skullcandy has addressed the vulnerability in Dime 3 firmware version 1.0.0.30.

Newer production units are expected to ship with the corrected firmware.
The difficulty is that the Dime 3 does not support firmware updates through the Skullcandy mobile app.
As a result, owners of earbuds running version 1.0.0.28 currently have no supported way to install the patched firmware themselves.
Owners of affected earbuds have limited options
For vulnerable units, the practical mitigation is to reduce opportunities for unwanted Bluetooth connections.
Turning the earbuds completely off when they are not being used limits exposure. Extra caution may also be sensible in crowded public places where many unknown Bluetooth devices are nearby.
The vulnerability does not mean every Dime 3 pair has been compromised, but owners running firmware 1.0.0.28 should be aware that the flaw can allow unauthorized pairing without the normal confirmation process.
The fixed firmware, version 1.0.0.30, closes that gap, but the lack of an update path for older units remains the main problem for existing owners.



Discussion (0)
Be the first to comment.