Skullcandy Dime 3 Lets Strangers Pair and Listen to Your Microphone
- The Mess: Skullcandy Dime 3 earbuds running firmware 1.0.0.28 accept Bluetooth pairing from an unknown device without the owner’s approval or putting the earbuds into pairing mode.
- The Damage: Someone within Bluetooth range can hijack the audio connection and access the headset microphone without touching the earbuds or getting a PIN.
- The Fix: Replace affected earbuds or move to firmware 1.0.0.30 if an authorized update path becomes available; existing 1.0.0.28 units currently have no consumer-accessible upgrade method.
This is one of those IoT bugs that sounds ridiculous until you look at what the attacker actually gets.
Skullcandy Dime 3 model S2DCW, running firmware 1.0.0.28, accepts a new Bluetooth Classic pairing request from a previously unpaired device without requiring the owner to put the earbuds into pairing mode.
No button press.
No PIN.
No passkey.
No confirmation.
No victim interaction.
CERT/CC published the vulnerability as VU#859658 on September 8, 2026. The underlying issue is associated with CVE-2025-20701, a flaw in the Airoha Bluetooth audio SDK that allows Bluetooth audio devices to be paired without user consent.
The Attacker Only Needs Bluetooth Range
This isn’t an internet attack.
The attacker needs to be close enough to communicate with the earbuds over Bluetooth.
That’s still enough in plenty of places.
A train.
An airport.
A conference.
An office.
A classroom.
A coffee shop.
The earbuds don’t need to be physically touched. CERT/CC says there is no requirement for prior pairing, access to the charging case or interaction with the device’s buttons.
The vulnerable Bluetooth Classic implementation accepts the pairing request and establishes the bond.
The attacker’s device then becomes a trusted device.
The Owner Gets the Warning Too Late
This is the particularly nasty part.
The legitimate user may eventually hear a “New device paired” notification.
But by then the pairing has already happened.
There is no confirmation dialog before the bond is established that gives the owner an opportunity to reject the connection.
Once bonded, the attacker can reconnect while remaining within radio range.
The attacker can establish an A2DP audio connection and interrupt the legitimate user’s active connection.
That’s annoying.
The microphone is where it becomes a security problem.
CERT/CC reports that the attacker can access the Dime 3’s Hands-Free/Headset profile and capture live microphone audio.
The earbuds have effectively become an unauthorized Bluetooth microphone.
The Bluetooth Stack Is the Real Culprit
The Dime 3 isn’t some exotic custom radio device.
Its Bluetooth PnP information identifies Airoha Technology Corp. as the chipset vendor, and the underlying vulnerability had already been tracked as CVE-2025-20701 in Airoha’s Bluetooth audio SDK.
That matters because the problem isn’t simply “Skullcandy forgot a pairing prompt.”
The product inherited vulnerable behavior from the Bluetooth audio software stack.
The Dime 3 became one of the affected products where that behavior could be reproduced.
There Is a Patch. That’s the Worst Part.
The vendor considers firmware 1.0.0.30 to contain the fix for CVE-2025-20701.
Normally, that would be the end of the story.
Update the earbuds.
Move on.
Except the Dime 3 does not support firmware updates through the Skullcandy application.
CERT/CC says Skullcandy confirmed that customers with existing units on firmware 1.0.0.28 currently have no known consumer-accessible way to install version 1.0.0.30.
So the security advice becomes awkward:
The fixed firmware exists, but affected owners cannot simply install it.
That’s a supply-chain problem, not just a coding problem.
What Should Owners Do?
First, check the firmware version.
If the Dime 3 reports 1.0.0.28, assume the Bluetooth pairing flaw applies.
Until a supported upgrade route becomes available:
- avoid using the earbuds in situations where unknown people can remain within Bluetooth range;
- pay attention to unexpected pairing notifications;
- remove unknown devices from the Bluetooth paired-device list;
- don’t assume disconnecting the attacker permanently removes the problem;
- contact Skullcandy for a supported replacement or remediation option.
There is no magic password change that fixes a vulnerable Bluetooth pairing implementation.
Bugstoday Opinion
This is exactly why “it’s only headphones” is a terrible security assumption.
The device has a radio.
It has firmware.
It authenticates other devices.
It carries audio.
It exposes a microphone.
That’s a computer with a much smaller screen.
The most uncomfortable detail isn’t even the unauthorized pairing.
It’s the firmware situation.
A patch exists.
The vulnerable devices are still out there.
And the normal update mechanism can’t install the patch.
For a product people wear next to their heads during calls, meetings and private conversations, that’s an ugly place to be.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- CERT/CC — VU#859658
- Carnegie Mellon Software Engineering Institute — VU#859658
- CVE-2025-20701
- Airoha Technology — Bluetooth Audio SDK
- Skullcandy — Dime 3 / S2DCW




