Skip to content
ThreatCluster

Skullcandy Dime 3 Earbuds Vulnerable to Bluetooth Hijacking

First seen 10 Sep 2026, 23:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 01:17 UTC
  • Skullcandy Dime 3 earbuds have a Bluetooth vulnerability allowing unauthorized pairing.
  • Attackers can hijack audio sessions and capture microphone audio without user consent.
  • Firmware updates to fix the vulnerability are not available for existing devices.

Skullcandy Dime 3 wireless earbuds, specifically model S2DCW running firmware version 1.0.0.28, are affected by an unauthenticated Bluetooth pairing vulnerability, tracked as VU#859658. This flaw allows attackers within Bluetooth range to pair with the earbuds without user consent, enabling them to hijack audio sessions and potentially capture microphone audio. The vulnerability was previously disclosed in CVE-2025-20701, published on 2025-08-04, with a proof-of-concept released on 2026-07-19. The earbuds do not support firmware updates through the Skullcandy app, leaving existing units vulnerable. Users receive only an audible notification after unauthorized pairing has occurred, providing no chance to prevent it. The vendor has released a patch in firmware version 1.0.0.30, but existing units cannot be updated. As of now, there are no known methods for consumers to update their devices. The vulnerability poses significant risks to user privacy and security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-08-04
CVE-2025-20701 published
A vulnerability in Airoha Bluetooth audio SDK allows pairing without user consent.
Kb.Cert
2026-07-19
First public PoC released
Proof-of-concept code for CVE-2025-20701 was made publicly available.
Kb.Cert
2026-09-08
Vulnerability disclosed by CERT
CERT Coordination Center reported the unauthenticated Bluetooth pairing vulnerability in Skullcandy Dime 3 earbuds.
Kb.Cert
2026-09-10
Gbhackers report on vulnerability
Gbhackers published an article detailing the Bluetooth flaw and its implications for user privacy.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track CVE-2025-20701 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed