Skullcandy Dime 3 Earbuds Vulnerable to Unauthorized Pairing and Eavesdropping
A critical Bluetooth flaw in Skullcandy Dime 3 earbuds allows nearby attackers to pair without permission, hijack audio, and spy via the microphone.

A significant security vulnerability has been discovered in Skullcandy's Dime 3 wireless earbuds, potentially allowing malicious actors to gain unauthorized access to the device. The flaw, identified as Vulnerability Note VU#859658 and CVE-2025-20701, affects units running firmware version 1.0.0.28. It enables attackers within Bluetooth range to pair with the earbuds without the owner's explicit consent or knowledge.
The vulnerability stems from an insecure implementation of Bluetooth Classic (BR/EDR) pairing within the Airoha Bluetooth audio software development kit, which Skullcandy utilizes. Unlike typical secure pairing processes that require user interaction, such as button presses or PIN confirmations, the affected Dime 3 earbuds reportedly accept pairing requests from unknown devices even when not in pairing mode. This bypasses standard security protocols designed to prevent unauthorized connections.
Exploiting this vulnerability requires no physical access to the earbuds or their case, nor does it necessitate any prior pairing relationship or interaction from the victim. An attacker simply needs to be within the typical operational range of Bluetooth and know or discover the target earbuds' Bluetooth Classic address. Once this address is known, the attacker can initiate a direct pairing request.
Because the earbuds employ a 'NoInputNoOutput' Bluetooth I/O capability, the pairing and bonding process can complete without any confirmation from the legitimate owner. This means an attacker's device can become a trusted connection, allowing it to automatically reconnect whenever it is in proximity. This creates an ongoing security risk beyond a single, isolated incident.
Once an unauthorized device is bonded, it can establish an Advanced Audio Distribution Profile (A2DP) connection. This allows the attacker to hijack the audio session, potentially interrupting the legitimate user's audio playback from their smartphone or computer. The attacker could then play their own audio through the earbuds or prevent the owner from accessing their intended audio stream. The only indication to the user that something has gone wrong is an audible announcement of a "New device paired."
More alarmingly, the vulnerability extends to the Hands-Free Profile (HFP) and Headset Profile (HSP). These profiles can grant attackers access to the earbuds' microphone functionality. This opens the door for attackers to potentially capture live audio from the victim's surroundings through the compromised Dime 3 earbuds, effectively turning them into eavesdropping devices.
A patch for this vulnerability is reportedly available in firmware version 1.0.0.30. However, Skullcandy has confirmed that the Dime 3 earbuds do not support firmware updates through their dedicated application. Consequently, existing units running the vulnerable firmware 1.0.0.28 are currently unpatchable by consumers, leaving them permanently exposed to this threat.
Users are advised to exercise caution, especially in public or shared spaces, and to be vigilant for unexpected pairing notifications. While there is no consumer-level fix, removing unfamiliar Bluetooth devices from paired lists on other devices may offer some mitigation. The lack of a firmware update mechanism for these earbuds means that the security flaw will persist for the lifespan of the affected devices.