important · Bluetooth — Earbuds
A nearby stranger can silently bond to Skullcandy Dime 3 earbuds and capture microphone audio.
Affects
Skullcandy Dime 3, consumer true-wireless earbuds running embedded Airoha Bluetooth firmware.
Within Bluetooth Classic range, an attacker can create a stored NoInputNoOutput bond while the earbuds are not in pairing mode, then reconnect for audio takeover and microphone access.
Detail and 6 sources
A fixed build exists, but no owner-accessible upgrade path for deployed units was established.
Chain to watch
Discover or obtain the earbuds' BR/EDR address.→↓Create a stored bond without pairing mode or owner confirmation.→↓Reconnect and open the microphone path.→↓Owners do not have an established route to the fixed firmware.
Unverified chainSkullcandy needs to identify how deployed retail units receive the fixed build.
Sources
ResearchDIME® 3Researchhttps://static.ernw.de/whitepaper/ERNW_White_Paper_74_1.0.pdfResearch'[FD] Skullcandy Dime 3 unauthorized Bluetooth pairing behavior' - MARCCode / PoCGitHub - x0jac0b0x/skullcandy-dime3-cve-2025-20701: Unauthorized Bluetooth Classic pairing behavior consistent with CVE-2025-20701 on Skullcandy Dime 3 earbuds. · GitHubVendorSkullcandy Dime 3 earbuds expose users to Bluetooth hijackingSecondaryCERT/CC Vulnerability Note VU#859658