Skullcandy Dime 3 Wireless Earbuds Exposed to Bluetooth Hijacking Due to Unpatchable Firmware Flaw

The Carnegie Mellon University CERT Coordination Center (CERT/CC) has issued a critical advisory warning that the popular Skullcandy Dime 3 wireless earbuds are vulnerable to a severe Bluetooth hijacking flaw. The security issue, officially tracked as CVE-2025-20701, allows nearby malicious actors to establish unauthorized connections to the audio devices without requiring user interaction, a physical pairing button press, or a PIN code.
The vulnerability stems from the implementation of the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (specifically model S2DCW running firmware version 1.0.0.28) utilizes to govern wireless connectivity and facilitate data transmission between the earbuds and paired host devices. While manufacturer updates have theoretically resolved the underlying software bug in newer production batches, a glaring logistical bottleneck has left consumers exposed: owners of existing units running the vulnerable firmware have no feasible, user-accessible mechanism to apply the necessary security patch.
The implications of this oversight extend far beyond simple audio disruption. Because affected units lack a self-service pathway to upgrade to firmware version 1.0.0.30, thousands of budget-conscious consumers—particularly young users drawn to the Dime 3’s accessible price point, bass-heavy audio profiles, and long battery life—are left with hardware that cannot be easily secured against proximity-based attacks.
Anatomy of the CVE-2025-20701 Vulnerability
At the heart of the crisis is a high-severity, missing-authentication vulnerability within the Airoha Bluetooth Audio SDK architecture. First uncovered by security researchers from ERNW and subsequently detailed at the TROOPER cybersecurity conference, the flaw highlights a systemic oversight in how certain hardware development kits handle incoming device pairing requests.
Under normal operating conditions, establishing a Bluetooth connection between a peripheral (such as a pair of wireless earbuds) and a host device (such as a smartphone or laptop) requires explicit user confirmation. This typically involves placing the earbuds into a designated pairing mode, selecting the device from a menu, and verifying a PIN or prompt. However, CVE-2025-20701 bypasses these safeguards entirely on vulnerable units.
An attacker positioned within close physical range—typically within Bluetooth broadcast distance (roughly 10 meters)—can transmit a pairing request that the Skullcandy Dime 3 automatically accepts. Crucially, this exploitation requires no physical contact with the charging case, no manual interaction from the earbud owner, and no knowledge of a pairing PIN.
Once the unauthorized connection is successfully established, the attacker’s device is classified by the earbuds as a "trusted" entity. Consequently, the rogue device gains the ability to automatically reconnect whenever it comes back into proximity with the target hardware. This persistent access opens the door to several malicious scenarios, including:
- Audio Interruption: Forcibly disconnecting the legitimate user from their media playback or phone call.
- Playback Hijacking: Streaming unauthorized audio, advertisements, or malicious prompts directly into the victim’s ears.
- Profile Access: Interacting with the headset profile to manipulate device states or settings.
- Eavesdropping and Microphone Capture: Leveraging the headset’s microphone to capture live audio, potentially intercepting private conversations, phone calls, or voice commands issued to a smartphone assistant.
While a target might occasionally perceive a brief audio dropout or notice a standard "new device paired" notification chime, these alerts are easily misinterpreted. Most users dismiss such occurrences as momentary Bluetooth interference or a standard connection hiccup, leaving the underlying compromise completely unnoticed.
A Timeline of the Airoha Bluetooth SDK Crisis
The discovery of CVE-2025-20701 is part of a broader, industry-wide reckoning regarding vulnerabilities in white-label and third-party Bluetooth chipsets. Because numerous audio equipment manufacturers rely on prefabricated SDKs and system-on-chip (SoC) architectures from suppliers like Airoha, software flaws discovered in a core development kit often ripple across multiple brands and product lines.
The chronology of events leading to the current Skullcandy advisory illustrates the complex path from vulnerability discovery to vendor remediation:
- Last Year: ERNW security researchers discover the missing-authentication flaw in the Airoha Bluetooth Audio SDK, subsequently presenting their findings at the TROOPER cybersecurity conference. The research proves that a broad range of earbud and headphone products from various global vendors are susceptible to proximity-based hijacking.
- August 4, 2025: Airoha officially publishes comprehensive SDK updates designed to mitigate the security flaws, distributing the patches to downstream hardware manufacturers so they can update their proprietary firmware builds.
- June 2025: Major consumer electronics brands begin rolling out fixes. For instance, Apple issues a targeted firmware update to resolve a similar iteration of the flaw affecting its Beats Studio Buds, closing potential spying vectors on its own hardware ecosystem.
- Recent Months: Security researcher Jacob Nowak submits a tip to the Carnegie Mellon University CERT Coordination Center regarding abnormal Bluetooth pairing behaviors observed in the budget audio market.
- CERT/CC Investigation: CERT/CC verifies that the vulnerability actively impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.
- August/September 2026: Skullcandy introduces firmware version 1.0.0.30, which internally addresses CVE-2025-20701. However, technical analysis confirms that end-users possess no pathway to install this update on legacy hardware.
The Patching Dilemma: Why Users Are Left Stranded

The most troubling dimension of the Skullcandy Dime 3 security advisory is not merely the existence of CVE-2025-20701, but the apparent impossibility of remediation for current owners. In modern consumer technology, users naturally expect that discovered software vulnerabilities will be resolved through standard over-the-air (OTA) updates, usually managed via a companion mobile application or an automated desktop utility.
However, CERT/CC’s public advisory explicitly highlights a critical operational barrier: existing units running the vulnerable firmware version 1.0.0.28 cannot currently be updated by customers through the official Skullcandy application or any other consumer-accessible interface.
"As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30," the CERT/CC advisory notes.
This hardware-software disconnect leaves consumers in an untenable position. While the manufacturer has engineered a backend fix (version 1.0.0.30), the lack of an accessible firmware flashing mechanism for legacy retail units means that the patch is effectively restricted to newly manufactured factory batches. Consumers who purchased their Dime 3 earbuds prior to the silent firmware transition are left with permanently vulnerable hardware unless they purchase a completely new unit—an expensive and environmentally wasteful solution to a software-originated security flaw.
Industry analysts and consumer advocacy groups have raised concerns regarding corporate transparency and accountability when hardware design precludes post-market security maintenance. Attempts by journalistic outlets, including BleepingComputer, to reach out to Skullcandy for clarification on how legacy users might safely upgrade their devices have faced hurdles, as the company’s automated support chatbot is currently unequipped to route or process specialized press inquiries regarding firmware accessibility.
Broader Implications for the Budget Audio Market
The Skullcandy Dime 3 incident casts a spotlight on the unique security challenges inherent in the booming market for budget and ultra-affordable consumer electronics. In a sector driven by aggressive price competition, manufacturing margins are razor-thin. To achieve low retail price points, companies frequently rely on pre-packaged, third-party chipset solutions and SDKs without maintaining complex backend infrastructure required for seamless, user-managed firmware maintenance over the device’s lifecycle.
While high-end audio brands—such as Apple, Sony, and Bose—maintain robust companion applications capable of pushing deep hardware-level updates directly to earbuds and headphones, budget brands often treat low-cost accessories as disposable commodities. Devices are manufactured, shipped, and sold with static firmware configurations that remain static from the factory floor to the landfill.
When a foundational vulnerability like CVE-2025-20701 impacts these budget-tier ecosystems, the systemic fallout is profound. Unlike enterprise software or high-end smartphones, where security patches are pushed globally within hours, physical audio peripherals lack the diagnostic ports, Wi-Fi modules, or sophisticated bootloaders that would allow everyday consumers to manually flash a secure ROM.
Furthermore, the nature of Bluetooth-based attacks means that exploitation does not require advanced technical sophistication once the vulnerability is understood. Automated proximity scanning scripts running on inexpensive single-board computers or modified smartphones could theoretically scan urban environments, public transit networks, or coffee shops for vulnerable MAC addresses associated with the Airoha SDK flaw, enabling mass, indiscriminate hijacking of personal audio gear.
Mitigation and Recommendations for Affected Users
Given the absence of a user-accessible firmware update path for Skullcandy Dime 3 units running version 1.0.0.28, cybersecurity experts recommend several defensive strategies to minimize the risk of unauthorized Bluetooth hijacking:
- Disable Bluetooth When Not in Use: When walking through crowded public areas, public transportation hubs, or dense urban environments where proximity attacks are most likely to occur, users should consider turning off their smartphone or laptop’s Bluetooth adapter if they are not actively listening to audio.
- Unpair and Store Safely: When the earbuds are not actively in use, keeping them inside their closed charging case can help mitigate exposure, though proximity pairing vulnerabilities in certain SDK implementations can occasionally accept connections even when the peripheral is idle. However, storing them out of immediate reach reduces the physical window of opportunity for localized attackers.
- Monitor for Anomalies: Users should remain vigilant for unexpected audio dropouts, sudden reconnections, or automated voice prompts indicating that a new device has been paired. If such behavior occurs without user intervention, it may indicate a localized sniffing or hijacking attempt.
- Contact Customer Support: Consumers affected by the inability to patch their devices are encouraged to reach out directly to Skullcandy customer service channels to inquire about potential hardware replacement programs, warranty claims, or authorized return policies for devices rendered insecure by unpatchable firmware limitations.
As the cybersecurity community continues to scrutinize the security posture of Internet of Things (IoT) devices and wireless peripherals, the Skullcandy Dime 3 case serves as a stark reminder that software security must be matched by accessible, robust lifecycle maintenance frameworks—ensuring that budget-friendly pricing does not come at the direct expense of consumer privacy and digital safety.







