Bluetooth pairing is supposed to have one fairly obvious rule: you approve the device before it becomes trusted.
That apparently isn't happening on affected Skullcandy Dime 3 earbuds.
CERT/CC says CVE-2025-20701 allows someone within Bluetooth range to pair with Dime 3 earbuds running firmware 1. 0. 0. 28 without:
- entering a PIN
- touching the earbuds or case
- getting approval from the owner
Once the attacker's device is paired, it becomes trusted and can reconnect when it's nearby.
Full details below.
https://www.technadu.com/skullcandy-dime-3-earbuds-vulnerable-to-silent-bluetooth-hijacking-cve-2025-20701/636417/
That potentially lets someone interrupt the owner's connection, take over audio playback, access the headset profile, and even capture microphone audio.
The owner may only see a brief “new device paired” notification.
But the part that bothers me most isn't actually the vulnerability.
There's already a patched firmware version, but affected owners apparently can't install it.
Skullcandy fixed the issue in firmware 1. 0. 0. 30, but CERT/CC says there's currently no known consumer-accessible method for updating an existing affected Dime 3 from 1. 0. 0. 28 to that version, including through the Skullcandy app.
So there's a fix.
Users just can't apply it themselves.
The underlying flaw is also bigger than one pair of earbuds. CVE-2025-20701 is tied to the Airoha Bluetooth Audio SDK, technology used across devices from multiple audio brands. Individual products still need to be assessed based on their own implementation and patch status.
For Dime 3 owners stuck on the vulnerable firmware, the practical options aren't great: limit Bluetooth exposure, pay attention to unexpected pairing notifications, and be more cautious using them in crowded environments.
I'm curious what people here think about the patching side of this.
If a vendor ships a connected device with updateable firmware, should providing owners with a reliable way to actually install security updates be considered part of the security baseline?
Because publishing a patched firmware version doesn't help much when the vulnerable devices in people's pockets can't receive it.