Security · September 17, 2026
Also published in Português (Brasil)
Critical Security Vulnerability Found in Cheap Bluetooth Earbuds
A critical security vulnerability has been discovered in the Skullcandy Dime 3 wireless earbuds, posing a serious risk to users. The CERT Coordination Center at Carnegie Mellon University announced that these devices can pair with foreign devices without user consent.
This situation can lead to disconnections for earbud owners and unauthorized access to played content. The device only provides an audio notification after a pairing has been made with a new device.
The vulnerability also allows access to the earbuds' microphone. As a result, attackers can record live audio without the user's knowledge.
Technical details of the vulnerability, identified as CVE-2025-20701, are not due to a software error directly produced by Skullcandy. The issue stems from Bluetooth system chips manufactured by Airoha, a company based in Taiwan.
Dennis Heinze and Frieder Steinmetz from ERNW disclosed this vulnerability at the TROOPERS conference in Heidelberg in June 2025. Although Airoha released an SDK update in June 2025 for this vulnerability, the situation is different for Dime 3 owners.
Different organizations have assessed the severity of the vulnerability differently. MediaTek rated it at 6.7, while CISA's vulnerability enrichment program categorized it as high with a score of 8.8.
Independent researcher Jacob Nowak shared his findings on the Full Disclosure mailing list at the beginning of August. Nowak proved the validity of this vulnerability through tests on his own hardware.
There is no update path for existing users to fix this issue. Skullcandy prepared a patch numbered 1.0.30 for devices using version 1.0.0.28, but this update is only available for newly manufactured earbuds. The lack of a supporting application means that this security vulnerability remains permanent on existing devices.
An attacker would need to be within a few meters of the victim to exploit this vulnerability. In more advanced scenarios requiring technical skills, risks such as accessing the phone's contact list or viewing call history could theoretically be possible. This situation reveals a scenario where users do not have full control over their own devices.