Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
AdvisorySkullcandy Dime 3Airoha Bluetooth Audio SDKOur summary
The CERT Coordination Center at Carnegie Mellon University has issued a warning regarding the Skullcandy Dime 3 wireless earbuds, which are susceptible to unauthorized Bluetooth pairing due to CVE-2025-20701. This high-severity flaw resides in the Airoha Bluetooth Audio SDK used by model S2DCW units running firmware version 1.0.0.28, allowing attackers within range to intercept calls, play audio, or monitor conversations without user consent or physical access. Although Skullcandy resolved the issue in firmware version 1.0.0.30, consumers with previously purchased devices have no official method to update their hardware, leaving them permanently exposed to these privacy risks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.