Skullcandy's Dime 3 wireless earbuds contain a Bluetooth vulnerability that can accept a pairing request from a stranger's device without any action from the owner, according to Carnegie Mellon University's CERT Coordination Center.
The resulting connection is permanent. The only notification is a spoken “new device paired” message after the pairing has occurred, with no user interaction required. The advisory was written by CERT/CC's Bob Kemerer and credits researcher Jacob Nowak, who described the issue on the Full Disclosure mailing list in early August.
Skullcandy addressed the flaw in units running firmware version 1.0.0.28 by releasing version 1.0.0.30. However, CERT says there appear to be no consumer-accessible methods to upgrade existing earbuds, because the companion app reportedly does not support firmware updates. The fix therefore seems limited to newly manufactured units.
The vulnerability, CVE-2025-20701, affects Bluetooth systems-on-chip from Airoha and was disclosed by ERNW researchers Dennis Heinze and Frieder Steinmetz in June 2025. MediaTek assigned it a 6.7 severity rating, while CISA later gave it an 8.8 rating and a high classification. Exploitation could include microphone recording; more advanced scenarios would require other exploits, technical skill, proximity within a few meters, and Bluetooth enabled on a paired smartphone.
Comments
0No comments yet. Be the first to comment.