Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone

A security vulnerability in Skullcandy Dime 3 wireless earbuds could allow nearby attackers to pair with the device without the owner’s approval, hijack audio playback, and potentially capture live microphone audio.

Tracked as Vulnerability Note VU#859658, the issue affects Skullcandy Dime 3 earbuds (model S2DCW) running firmware version 1.0.0.28.

The flaw was publicly disclosed on September 8, 2026, and is linked to CVE-2025-20701, an authentication weakness in the Airoha Bluetooth audio software development kit.

The vulnerability stems from insecure Bluetooth Classic (BR/EDR) pairing behavior. Normally, wireless earbuds must be deliberately placed into pairing mode before a new phone, laptop, or other device can connect.

Skullcandy Dime 3 Bluetooth Flaw

Users may also be required to press a button, confirm a prompt, enter a PIN, or accept a passkey request. However, affected Dime 3 earbuds reportedly accept a pairing request from an unknown Bluetooth device even when the owner has not activated pairing mode.

The attack does not require physical access to the earbuds, their charging case, or their buttons. It also does not need a prior pairing relationship, PIN, passkey, or any interaction from the victim.

An attacker only needs to be within normal Bluetooth radio range and know or discover the target earbuds’ Bluetooth Classic address. They can then send a direct pairing request to the device.

Because the earbuds use a NoInputNoOutput Bluetooth I/O capability, the pairing and bonding process can complete without the owner confirming the connection.

Once the attacker’s device is bonded, it becomes a trusted Bluetooth device. This means it can automatically reconnect to the earbuds whenever it is nearby, creating an ongoing risk rather than a one-time disruption.

The attacker could establish an Advanced Audio Distribution Profile (A2DP) connection and take over the earbuds’ audio session. This could interrupt the legitimate user’s connection to their smartphone or computer, allowing the attacker to play audio through the earbuds or deny the owner access to their active audio stream.

The only warning the user reportedly receives is an audible “New device paired” announcement. By the time the user hears that message, the unauthorized pairing has already succeeded, and the user has no opportunity to reject it before the attacker is trusted.

More concerningly, an attacker may also access the earbuds’ Hands-Free Profile or Headset Profile. These Bluetooth profiles can expose microphone functionality, potentially allowing the attacker to capture live audio from the victim’s surroundings through the Dime 3 microphone.

The underlying flaw was previously identified as CVE-2025-20701 in Airoha Bluetooth audio SDK implementations. Airoha is identified through the Dime 3 Bluetooth Plug and Play modalias, which lists Airoha Technology Corp. under Bluetooth SIG company ID 0x0094.

According to CERT/CC reports, a patch is reportedly available in firmware version 1.0.0.30. However, Skullcandy confirmed that Dime 3 earbuds do not support firmware updates through the Skullcandy application.

As a result, customers with existing units running firmware 1.0.0.28 currently have no known consumer-accessible way to install the fixed firmware.

Users should avoid using affected earbuds in locations where unknown people may be within Bluetooth range, remain alert for unexpected pairing notifications, and remove unfamiliar Bluetooth devices from paired-device lists where possible.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone appeared first on Cyber Security News.