TechNewsReel
Live

Skullcandy Dime 3 Earbuds Vulnerable to Zero-Click Bluetooth Hijacking

A critical flaw in the Airoha Bluetooth SDK allows attackers to hijack audio and access microphones without user consent.

TechNewsReel Newsroom · September 10, 2026

Owners of Skullcandy Dime 3 wireless earbuds are facing a critical security risk that allows nearby attackers to hijack audio sessions and eavesdrop on private conversations. The vulnerability enables unauthorized Bluetooth pairing without any user interaction or physical confirmation, effectively turning the earbuds into an open gateway for attackers within radio range.

According to the Carnegie Mellon University CERT Coordination Center (CERT/CC), the flaw affects the Skullcandy Dime 3 (Model S2DCW) running firmware version 1.0.0.28. Once an attacker successfully pairs with the device, they can seize control of the audio output or access the earbuds' microphone to capture live audio. The vulnerability is tracked as CVE-2025-20701 and originates from the Airoha Bluetooth audio SDK integrated into the hardware.

The Technical Root

The security breach stems from the earbuds' "NoInputNoOutput" I/O capability. This specific configuration allows Bluetooth Classic (BR/EDR) pairing requests to be completed without the requirement of a PIN, a passkey, or a physical button press. Because the hardware does not require a handshake or user approval to establish a connection, the exploitation is categorized as "zero-click," meaning the victim does not have to perform any action for the attack to succeed.

Industry Implications

This vulnerability highlights a systemic risk in the supply chain of Bluetooth audio components. Because the flaw exists within the Airoha SDK—a third-party software development kit used by various hardware manufacturers—the issue is not unique to Skullcandy's design but is inherited from the underlying components. For the user, the consequence is a total loss of privacy; an attacker in a crowded area, such as a cafe or airport, could potentially listen to a user's environment or interrupt their audio stream without the user ever knowing how the connection was established.

The Patching Deadlock

While a technical fix exists in firmware version 1.0.0.30, users are left in a precarious position. CERT/CC reports that Skullcandy confirmed the Dime 3 does not support firmware updates through the official Skullcandy mobile application. Consequently, there is currently no consumer-accessible method for users to update their units from the vulnerable 1.0.0.28 version to the patched version. This leaves existing affected units permanently exposed to the hijacking flaw, as the hardware lacks the necessary update infrastructure to deploy the fix to the public.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.