Skullcandy Dime 3 earbuds are affected by a Bluetooth vulnerability that could allow a nearby attacker to connect without the owner’s permission, while customers have no known way to install the firmware update that fixes it.
The warning was issued by Carnegie Mellon University’s CERT Coordination Center (CERT/CC), which said devices running firmware version 1.0.0.28 accept pairing requests from previously unpaired Bluetooth devices without requiring user approval.
The flaw, identified as CVE-2025-20701, is rated high severity and affects the Airoha Bluetooth Audio software development kit used by the Dime 3, also known as model S2DCW, to manage wireless connections.
An attacker would need to be within Bluetooth range, but would not require a pairing PIN, physical access to the earbuds’ charging case or confirmation from the owner. Once connected, the attacker’s device could become trusted and reconnect automatically when nearby.
CERT/CC said this could allow someone to disrupt the owner’s connection, take control of audio playback, access the headset profile and capture sound from the earbuds’ live microphone.
Some users may hear a “new device paired” alert after an unauthorised connection. However, the warning could be overlooked or mistaken for a brief interruption followed by the earbuds reconnecting to their usual device.
Skullcandy Dime 3 update unavailable to customers
Skullcandy has said the problem was resolved in firmware version 1.0.0.30. But CERT/CC said owners of affected earbuds currently have no consumer-accessible method to move from the vulnerable version to the safer release, either manually or through the Skullcandy app.
“Existing units running the vulnerable firmware cannot currently be updated by customers through the app,” the advisory states.
It adds: “As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30.”
The Dime 3 is a relatively low-cost wireless earbud model marketed for features including bass-focused sound and extended battery life. The lack of an accessible update leaves customers who bought units with the earlier software unable to apply the manufacturer’s stated fix.
The vulnerability was discovered by researchers at ERNW and presented at the TROOPER cyber security conference last year. It is linked to a wider authentication weakness in Airoha’s Bluetooth Audio SDK affecting earbud and headphone products made by several manufacturers.
Airoha released software development kit updates addressing the issue on August 4 2025. Other manufacturers have since incorporated the fixes into product firmware, while Apple issued an update for its Beats Studio Buds in June.
