CVE Tools

CERT предупреждает о небезопасности наушников Skullcandy

Хакер (xakep.ru)By Мария Нефёдова

AdvisorySkullcandy Dime 3Airoha Bluetooth Audio SDK

Our summary

CERT/CC has highlighted that Skullcandy Dime 3 headphones accept Bluetooth pairing requests without owner confirmation, allowing nearby attackers to intercept audio and access the microphone. This issue stems from CVE-2025-20701 in the Airoha Bluetooth Audio SDK, affecting devices running firmware 1.0.0.28. While Airoha released a patch in August 2025 and Skullcandy fixed it in firmware 1.0.0.30, users with older firmware currently have no way to apply the update via the Skullcandy app or manual methods.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store