A high-severity Bluetooth flaw in Skullcandy Dime 3 wireless earbuds exposes users to hijacking and microphone access, with no consumer-facing fix available for affected devices on firmware version 1.0.0.28.
CERT/CC has warned that Skullcandy Dime 3 wireless earbuds can accept Bluetooth pairing requests from nearby unpaired devices without any user interaction, leaving owners exposed to hijacking of audio and microphone access. The issue affects units running firmware version 1.0.0.28 and is tracked as CVE-2025-20701, a high-severity flaw in the Airoha Bluetooth Audio SDK used by the earbuds for wireless communication, according to the advisory and reporting by BleepingComputer.
The vulnerability allows an attacker within range to connect without a pairing PIN, physical access to the case, or approval from the owner. Once paired, the rogue device can become trusted and reconnect automatically when nearby, which may let an attacker interrupt the legitimate connection, seize audio playback, access the headset profile and, in some cases, capture live microphone audio, BleepingComputer said. The user may only notice a brief pairing notification or what appears to be a temporary connection drop.
According to researchers, the flaw was first identified by ERNW and presented at the TROOPER cybersecurity conference last year. Airoha issued SDK updates on 4 August 2025, and other manufacturers later adopted fixes, including Apple, which pushed a firmware update for its Beats Studio Buds this June. BleepingComputer also reported that CERT/CC received a tip from researcher Jacob Nowak before confirming the Dime 3 was affected.
Skullcandy says the problem was addressed in firmware version 1.0.0.30, but CERT/CC notes that consumers who bought vulnerable units have no practical way to install the fix through the Skullcandy app. The advisory states that existing devices on firmware 1.0.0.28 cannot currently be updated by customers, leaving them without a consumer-accessible route to a safe release.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





