CVE Tools

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

BleepingComputerBy Bill Toulas

AdvisorySkullcandy Dime 3Airoha Bluetooth Audio SDK

Our summary

The CERT Coordination Center at Carnegie Mellon University has issued a warning regarding the Skullcandy Dime 3 wireless earbuds, which are susceptible to unauthorized Bluetooth pairing due to CVE-2025-20701. This high-severity flaw resides in the Airoha Bluetooth Audio SDK used by model S2DCW units running firmware version 1.0.0.28, allowing attackers within range to intercept calls, play audio, or monitor conversations without user consent or physical access. Although Skullcandy resolved the issue in firmware version 1.0.0.30, consumers with previously purchased devices have no official method to update their hardware, leaving them permanently exposed to these privacy risks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store