Skullcandy Dime 3 Earbuds Vulnerable to Bluetooth Hijacking, No User Fix Available
A high-severity vulnerability, **CVE-2025-20701**, in the **Airoha Bluetooth Audio SDK** exposes **Skullcandy Dime 3** wireless earbuds to Bluetooth hijacking. The flaw allows nearby unpaired devices to connect without user interaction, and critically, users with affected firmware versions currently have no means to update their devices to a patched version.

The **Carnegie Mellon University CERT Coordination Center (CERT/CC)** has issued a warning regarding a significant security flaw impacting **Skullcandy Dime 3** wireless earbuds.
### Critical Bluetooth Flaw Identified
The vulnerability, tracked as **CVE-2025-20701**, affects devices running firmware version 1.0.0.28. It resides within the **Airoha Bluetooth Audio SDK**, which the **Skullcandy Dime 3** (model S2DCW) utilizes for its wireless connectivity.
This high-severity issue is a missing-authentication problem, allowing nearby unpaired devices to accept Bluetooth pairing requests without requiring a PIN, physical access to the earbud case, or any user approval.
### The Impact of Exploitation
Discovered by **ERNW** researchers and presented at a **TROOPER** cybersecurity conference, the flaw enables an attacker in close proximity to establish a connection. Once paired, the attacker's device becomes trusted, allowing automatic reconnection when nearby.
This grants the attacker the ability to interrupt the ownerβs connection, hijack audio playback, access the headset profile, and even capture live microphone audio. While the target might hear a βnew device pairedβ notification, it can be easily missed or dismissed as a momentary connection disruption.
### Patch Available, But Inaccessible to Users
**Airoha** released SDK updates to address the issue on August 4, 2025, with earbud manufacturers subsequently integrating these fixes. For instance, **Apple** addressed a similar flaw for its **Beats Studio Buds** via a firmware update released in June.
**Skullcandy** itself pushed an update for **CVE-2025-20701** in firmware version 1.0.0.30. However, a critical issue remains: **CERT/CC** notes that users who purchased earbuds with the earlier, vulnerable firmware (1.0.0.28) have no method to upgrade to the safe version.
βExisting units running the vulnerable firmware cannot currently be updated by customers through the app,β the advisory explains. βAs of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30.β
This means a significant number of users, particularly those who bought the popular and affordable **Skullcandy Dime 3** earbuds earlier, remain exposed to this Bluetooth hijacking threat with no immediate recourse.