Skullcandy Dime 3 Earbuds Exposed to Bluetooth Hijacking Vulnerability
A recent discovery by the Carnegie Mellon University CERT Coordination Center (CERT/CC) has shed light on a critical vulnerability affecting Skullcandy’s popular Dime 3 wireless earbuds. The issue, tracked as CVE-2025-20701, allows attackers in close proximity to connect to the device without requiring user interaction or authentication.
The problem lies in the Airoha Bluetooth Audio SDK, which is used by many earbud manufacturers, including Skullcandy. This vulnerability was first discovered last year by researchers at ERNW and presented at the TROOPER cybersecurity conference. Despite patches being released by Airoha in August 2025, some devices remain vulnerable, including the Skullcandy Dime 3 running firmware version 1.0.0.28.
The consequences of this vulnerability are severe. Once an attacker has paired with the device, they can hijack audio playback, access sensitive information, and even capture live microphone audio. The user may not even be aware that their device has been compromised, as the attacker’s device becomes trusted and can automatically reconnect when nearby. A notification indicating a “new device paired” may appear, but it is easy to miss or dismiss.
The affected earbuds are extremely popular among young users seeking affordable products with good sound quality. However, those who purchased their Dime 3 earbuds before the firmware update may be stuck with vulnerable devices. CERT/CC notes that there is currently no way for customers to manually upgrade to a safe version of the firmware, as the update process is not available through the Skullcandy app.
This vulnerability highlights the importance of regular firmware updates and the need for manufacturers to provide consumers with easy-to-use update mechanisms. Users are advised to check their device’s firmware version and take action if necessary. In this case, however, it seems that many users will be left vulnerable until a solution is found.
As we continue to rely on connected devices in our daily lives, it becomes increasingly clear that the security of these devices must be taken seriously. Manufacturers have a responsibility to ensure that their products are secure and up-to-date, and consumers must remain vigilant in protecting themselves from potential threats.
Source: Bleeping Computer — 2026-09-09