Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to silently pair with the earbuds, disrupt legitimate audio sessions, and potentially capture microphone audio.
This issue, tracked as VU#859658 by the CERT Coordination Center, affects the Skullcandy Dime 3 earbuds (model S2DCW) running firmware version 1.0.0.28.
CERT disclosed the vulnerability on September 8, 2026, warning that the earbuds accept Bluetooth Classic pairing requests from unknown devices even when the owner has not activated the pairing mode.
Skullcandy Dime 3 Bluetooth Flaw
The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094.
Normally, a Bluetooth audio device requires a deliberate user action, such as placing the earbuds in pairing mode through the charging case or using physical controls, to allow pairing.
However, the vulnerable firmware in the Dime 3 earbuds apparently accepts direct Bluetooth Classic BR/EDR pairing requests from previously unpaired devices without requiring any action from the owner.
An attacker only needs to be within Bluetooth range of the earbuds and know, discover, or obtain their Bluetooth Classic device address. No prior connection, PIN, passkey, button press, or physical access to the earbuds or charging case is necessary.
The pairing process completes because the earbuds use a NoInputNoOutput Bluetooth I/O capability. This setup does not let the owner review, reject, or confirm pairing attempts. Consequently, an attacker can bond their device as a trusted connection before the legitimate owner can intervene.
Once an attacker successfully pairs with the earbuds, their device can reconnect automatically whenever it is within range. CERT stated that the attacker can establish an Advanced Audio Distribution Profile (A2DP) connection, potentially disrupting the owner’s active connection to their phone, computer, or any other paired device.
This unauthorized connection could effectively hijack the audio session, enabling the attacker to send audio to the earbuds while disconnecting or interrupting the legitimate audio stream.
Although the earbuds provide a “New device paired” audio notification after the unauthorized pairing succeeds, this notification is not a meaningful preventive warning, as it occurs only after the attacker has already been added as a trusted device.
Moreover, an attacker can also connect through the Hands-Free Profile or Headset Profile. This capability could allow the attacker to capture live microphone audio, raising privacy concerns for users wearing the earbuds in public places, offices, transport hubs, or shared work environments.
CERT said Skullcandy considers firmware version 1.0.0.30 effective against CVE-2025-20701. However, Skullcandy confirmed that Dime 3 earbuds do not support firmware updates through the Skullcandy mobile application.
As a result, consumers using earbuds with firmware version 1.0.0.28 currently have no known way to upgrade to the patched version. This lack of an end-user update option leaves affected devices vulnerable, despite the fix.
Users are advised to remain vigilant for unexpected pairing notifications, remove unfamiliar Bluetooth connections when possible, and avoid using the earbuds for sensitive calls in places where attackers might be nearby.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

