A Critical Bluetooth Vulnerability Exposes Skullcandy Earbuds to Hijacking
Users of Skullcandy Dime 3 wireless earbuds are at risk of having their devices taken over by attackers thanks to a critical vulnerability in the earbuds’ Bluetooth connectivity. The issue, known as CVE-2025-20701, allows an attacker to connect to a vulnerable device without needing permission from the owner.
This is not just a theoretical risk – it’s a real-world threat that could be exploited by anyone with access to the earbuds. Once connected, an attacker can interrupt audio playback, access sensitive information stored on the device, and even capture live microphone audio. The worst part? Users may not even notice anything out of the ordinary happening.
The vulnerability is linked to the Airoha Bluetooth Audio SDK, which is used by multiple earbud manufacturers, including Skullcandy. Although a fix was released in August 2025, users who purchased their earbuds with an earlier firmware version are stuck – they have no way to update to a safe version without manually contacting Skullcandy support.
The CERT Coordination Center at Carnegie Mellon University discovered the issue after receiving a tip from researcher Jacob Nowak. According to their findings, an attacker can connect to a vulnerable device using Bluetooth pairing requests without needing a PIN or any form of permission. This means that even if you’re not actively using your earbuds, an attacker could still connect and take control.
Skullcandy has pushed out a firmware update (version 1.0.0.30) that fixes the vulnerability, but it’s unclear how many users will be able to access this update. The company’s chatbot is unable to handle press requests, leaving users in the dark about their options for upgrading to a safe version.
This incident highlights the importance of keeping your devices up-to-date with the latest security patches. It also underscores the need for manufacturers to provide clear and accessible instructions for updating firmware – especially when it comes to critical vulnerabilities like this one.
If you’re a Skullcandy Dime 3 user, take immediate action to protect yourself: contact Skullcandy support to see if they can provide guidance on updating your firmware. In the meantime, be extra cautious about leaving your earbuds unattended in public – and always keep an eye out for any suspicious connection requests or notifications on your device. By being aware of this vulnerability and taking proactive steps, you can minimize your risk of falling victim to a Bluetooth hijacking attack.
Source: Bleeping Computer — 2026-09-09