CERT предупреждает о небезопасности наушников Skullcandy
AdvisorySkullcandy Dime 3Airoha Bluetooth Audio SDKOur summary
CERT/CC has highlighted that Skullcandy Dime 3 headphones accept Bluetooth pairing requests without owner confirmation, allowing nearby attackers to intercept audio and access the microphone. This issue stems from CVE-2025-20701 in the Airoha Bluetooth Audio SDK, affecting devices running firmware 1.0.0.28. While Airoha released a patch in August 2025 and Skullcandy fixed it in firmware 1.0.0.30, users with older firmware currently have no way to apply the update via the Skullcandy app or manual methods.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.