CERT/CC warns that Skullcandy Dime 3 earbuds running firmware 1.0.0.28 accept Bluetooth pairing from nearby unpaired devices without user interaction, exposing users to rogue device access and audio hijacking. The flaw, tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, was fixed in firmware 1.0.0.30, but existing customers currently have no consumer-accessible way to update affected units. #CERTCC #SkullcandyDime3 #CVE202520701 #AirohaBluetoothAudioSDK
Keypoints
- Skullcandy Dime 3 earbuds are vulnerable to unauthorized Bluetooth pairing.
- The issue affects devices running firmware version 1.0.0.28.
- The flaw is tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK.
- An attacker nearby can hijack audio, reconnect automatically, and capture microphone audio.
- Skullcandy fixed the bug in firmware 1.0.0.30, but users cannot currently update affected units themselves.