“Existing units running the vulnerable firmware cannot currently be updated by customers through the app,” the advisory explains, a blunt admission from the Carnegie Mellon University CERT Coordination Center (CERT/CC) that leaves owners of a popular, low-cost Bluetooth earbud with a difficult choice: use potentially compromised hardware or discard it.
CVE-2025-20701 and the Airoha Bluetooth Audio SDK
CERT/CC warns that the high-severity vulnerability tracked as CVE-2025-20701 resides in the Airoha Bluetooth Audio SDK and manifests as a missing-authentication flaw. The SDK handles wireless connectivity and the communications stack used by a range of earbud and headphone products across multiple vendors. Airoha published SDK updates to address the issue on August 4, 2025; manufacturers have since adopted fixes for the broader ecosystem.
How the flaw works on the Skullcandy Dime 3 (firmware 1.0.0.28)
After receiving a tip from researcher Jacob Nowak, CERT/CC confirmed that the Skullcandy Dime 3 (model S2DCW) running firmware version 1.0.0.28 accepts Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. An attacker in close range can connect without a pairing PIN, without physical access to the earbuds’ case, and without an approving pairing request.
Once the attacker’s device pairs, it becomes trusted and will automatically reconnect when nearby. That trusted status allows the attacker to interrupt the legitimate owner’s connection, hijack audio playback, access the headset profile, and capture live microphone audio. The owner may hear a “new device paired” notification after the rogue pairing, but CERT/CC notes this is easy to miss or dismiss as a momentary glitch.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogDiscovery, vendor fixes, and related patches
The missing-authentication problem was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year. Following ERNW’s disclosure and Airoha’s SDK update on August 4, 2025, several vendors moved to close the gap in their products. The advisory notes that Apple addressed the flaw for its Beats Studio Buds with a firmware update released "this June." Skullcandy also pushed a fix for CVE-2025-20701 in firmware version 1.0.0.30.
That chain — independent researcher discovery, SDK vendor remediation, and manufacturer firmware updates — outlines the technical path from discovery to mitigation. But the practical effect for end users depends on whether that firmware actually reaches devices in consumers’ hands.
Firmware update availability and the consumer gap
CERT/CC explicitly reports that regular Skullcandy customers who bought Dime 3 units with the vulnerable firmware have no consumer-accessible way to install the patched firmware 1.0.0.30. The advisory states: “As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30.” BleepingComputer also attempted outreach and reported being unable to contact Skullcandy about users’ inability to upgrade, noting that the company's chatbot does not handle press requests.
Skullcandy’s firmware push exists in principle, but the absence of a user-facing update path means the technical fix does not automatically translate into consumer protection for affected units.
What this means for end users, technologists, and adversaries
- End users and the general public: Owners of Dime 3 earbuds should confirm which firmware their devices shipped with; units running firmware 1.0.0.28 are described as vulnerable. Because there is currently no consumer path to upgrade those units to 1.0.0.30, users face a realistic risk that a nearby attacker could pair and hijack their audio and microphone.
- Technologists and security teams: The incident illustrates how an SDK-level missing-authentication flaw can cascade across many device models. Teams maintaining device fleets or advising consumers should track vendor firmware availability and validate whether field units can be updated, not just whether a patch exists upstream.
- Adversaries and threat actors: The vulnerability provides a low-barrier privilege escalation in close-range scenarios: no PIN, no physical case access, and no user approval required. The ease of turning a paired attacker device into a persistent trusted device is the feature adversaries would exploit.
The record here is straightforward and stark: a widely used SDK defect (CVE-2025-20701) was patched upstream and vendors issued fixes, yet at least one popular product—Skullcandy Dime 3 units shipped with firmware 1.0.0.28—remains exposed in the hands of consumers without a way to receive the safe firmware 1.0.0.30. The situation leaves open a concrete question the advisory itself raises: how will Skullcandy enable affected customers to reach the patch that already exists?
Original reporting: https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/




