Skullcandy Dime 3 Earbuds Have Bluetooth Flaw Exposing Microphones
A critical Bluetooth security vulnerability has been identified in the Skullcandy Dime 3 wireless earbuds, exposing users to potential remote attacks without their knowledge or consent.
The flaw, tracked as CVE-2025-20701, affects devices running firmware version 1.0.0.28 and stems from an unauthenticated pairing issue within the "Airoha" Bluetooth Audio SDK used by Skullcandy. Cybersecurity researchers at ERNW originally identified this missing-authentication bug in the Bluetooth stack. The core problem is that the earbuds' "NoInputNoOutput" (NIO) profile accepts incoming connection requests automatically, bypassing standard security measures like PIN entry, passkeys, physical button presses, or manual pairing mode activation.
Once an attacker within wireless radio range initiates a Bluetooth Classic request to the Dime 3s, the unauthorized pairing sequence completes instantly. The rogue device is then added to the earbuds' trusted list, allowing it to reconnect automatically whenever it comes back into range. This hijacking enables attackers to disrupt active audio sessions using A2DP streams or play arbitrary audio directly into the victim's ears.
Perhaps more concerning is the access to the built-in microphones via the Hands-Free/Headset profile (HFP/HSP). This transforms the earbuds into a remote eavesdropping tool, streaming live ambient room audio to an attacker. The only indication of such an intrusion is a brief chime or an automated "New device paired" prompt, which plays only after the connection has already succeeded. In noisy public environments like cafes, transit hubs, or airports, users are highly likely to miss this subtle audio cue entirely.
Skullcandy and Airoha have acknowledged the issue. Airoha has issued SDK patches, and Skullcandy resolved the vulnerability in firmware version 1.0.0.30. However, a significant limitation remains: the Dime 3 does not support over-the-air (OTA) firmware updates via the mobile app. Consequently, owners of units currently running the vulnerable 1.0.0.28 firmware have no official way to upgrade to the patched version.
Until an OTA update is available or a new batch with the fixed firmware is released, users are advised to power off their earbuds completely when not in use or keep them out of Bluetooth range of untrusted devices in public spaces. For those shopping for the Dime 3, which is currently priced at $24.99 (down from $34.99), it is crucial to verify whether the specific unit being purchased includes the patched firmware version 1.0.0.30 or later.