Mastodon Mastodon Mastodon Mastodon

CERT/CC warns: Skullcandy Dime 3 earbuds vulnerable to unauthorized Bluetooth pairing with no update path

Photo of author

CyberSecureFox Editorial Team

Published:

The CERT Coordination Center (CERT/CC) has published advisory VU#859658 describing a vulnerability in the Skullcandy Dime 3 wireless earbuds (model S2DCW) running firmware version 1.0.0.28. The devices accept Bluetooth pairing requests from previously unknown devices without putting the earbuds into pairing mode and without any physical confirmation by the owner. According to CERT/CC, after a successful connection the attacker can intercept the audio stream and record sound from the earbuds’ microphone. The situation is aggravated by the fact that a patch exists in firmware version 1.0.0.30, but owners of already purchased devices have no available way to install the update.

Technical details of the vulnerability

The issue is tracked as CVE-2025-20701 and is related to the Bluetooth Audio SDK from Airoha Technology Corp., whose chipset is used in the Skullcandy Dime 3. According to the entry in the GitHub Advisory Database, the vulnerability is classified as CWE-863 (incorrect authorization) and has been assigned a score of 8.8 out of 10 under CVSS v3.1 (vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), corresponding to the High severity level.

According to the CERT/CC advisory, to exploit the vulnerability an attacker only needs to be within Bluetooth range. The following are not required:

  • prior pairing with the earbuds;
  • physical access to the device or its case;
  • entering a PIN code or access key;
  • any interaction from the owner.

The earbuds use the NoInputNoOutput I/O capability, which means the pairing and bonding process to establish a trusted connection is completed automatically without user involvement. A direct pairing request is sent to the known or discovered Bluetooth Classic (BR/EDR) address of the earbuds.

Consequences of exploitation

According to CERT/CC, after unauthorized pairing the attacker’s device is added to the trusted list and can subsequently reconnect automatically whenever it is within Bluetooth range. This enables the following:

  • establishing an A2DP audio transport, which interrupts the legitimate user’s active connection to their own device;
  • interception of the audio stream being played back;
  • access to the Hands-Free/Headset profile and capture of audio from the earbuds’ microphone in real time.

The only indicator for the owner is the voice prompt “New device paired”, which is played after the unauthorized pairing has already been completed — meaning the connection cannot be blocked in advance.

The update problem: a patch with no delivery

The most significant aspect of this vulnerability is not the technical flaw itself, but the inability of existing users to remediate it. According to the CERT/CC advisory, the fix is included in firmware version 1.0.0.30, which the manufacturer considers effective. However, Skullcandy Dime 3 earbuds do not support firmware updates via the Skullcandy app, and at the time the advisory was published there was no known method available to consumers to update from version 1.0.0.28 to 1.0.0.30.

It is worth noting a contradiction within the CERT/CC advisory itself: the “Solution” section refers to confirmation from Skullcandy regarding update limitations, while the vendor information section states that CERT/CC has not received an official statement from the vendor. This means that the nature of the communication between CERT/CC and Skullcandy remains unclear, and the claim of manufacturer confirmation should be viewed with this caveat in mind.

New batches of Dime 3 could theoretically be shipped with the fixed firmware already installed, but for owners of previously purchased devices the situation is effectively hopeless.

Scope and context of the problem

The confirmed scope of the vulnerability is limited to a specific model: Skullcandy Dime 3 (S2DCW) with firmware 1.0.0.28. Although CVE-2025-20701 describes an issue in the Airoha Bluetooth Audio SDK used by many manufacturers, the entry in the GitHub Advisory Database does not list specific affected and fixed SDK versions, leaving them as “Unknown”. Therefore, it would be incorrect to apply the conclusions of this advisory to all devices based on Airoha chipsets without additional confirmation.

At the time of publication there was no information about active exploitation of the vulnerability in real-world attacks. CVE-2025-20701 is not listed in the CISA KEV catalog.

Recommendations

Since a software-based remediation path is unavailable for existing devices, possible risk reduction measures are limited:

  • Awareness: pay attention to unexpected voice prompts about pairing with a new device — this may indicate unauthorized pairing.
  • Physical control: keep the earbuds in a closed case when not in use to minimize the attack window.
  • Risk assessment: if the earbuds are used in environments where call confidentiality is critical, consider replacing them with a model that supports firmware updates and has a stricter pairing procedure.
  • Firmware check: when purchasing new Skullcandy Dime 3 earbuds, make sure the device ships with firmware version 1.0.0.30 or later.

The Skullcandy Dime 3 case highlights a systemic problem in consumer electronics: a chip vendor may have a patch, but it is useless if the end device has no update delivery mechanism. Owners of affected earbuds who use them for confidential calls or in crowded public places should evaluate whether the eavesdropping risk via the microphone justifies continued use of this device — and, if necessary, switch to a model that supports updates.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.