Skullcandy Earbuds Vulnerability Allows Unauthorized Bluetooth Pairing and Audio Hijacking

A high-severity flaw in the Airoha Bluetooth Audio SDK, tracked as CVE-2025-20701, affects Skullcandy Dime 3 earbuds running firmware 1.0.0.28, allowing nearby attackers to pair without user interaction. Once connected, an attacker can intercept audio, access the headset profile, and capture microphone input. Although Skullcandy released a fixed firmware version 1.0.0.30, users have no way to update their devices, leaving many units vulnerable.
The vulnerability was uncovered by ERNW researchers and presented at the TROOPER conference. It stems from a missing-authentication flaw in the Airoha Bluetooth Audio SDK, affecting multiple headphone brands. Airoha released SDK patches in August 2025, and Apple subsequently updated its Beats Studio Buds in June.
Once a rogue device pairs, it gains trusted status and can automatically reconnect, allowing attackers to seize audio playback and access the microphone. While Skullcandy issued firmware 1.0.0.30, CERT/CC confirms no consumer-accessible path exists to upgrade existing Dime 3 units from the vulnerable 1.0.0.28 version.
This vulnerability could expose everyday consumers, particularly younger users drawn to the affordable Dime 3, to privacy invasions. An attacker within Bluetooth range may silently intercept private conversations or hijack music playback. The lack of a user-updatable firmware path means affected owners may remain exposed indefinitely. While the attack requires close physical proximity, the potential for covert microphone access could erode trust in consumer IoT devices, prompting users to reconsider the security of their personal audio gear.