MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-09 · via BleepingComputer

Skullcandy Earbuds Vulnerability Allows Unauthorized Bluetooth Pairing and Audio Hijacking

Image via BleepingComputer
Image via BleepingComputer

A high-severity flaw in the Airoha Bluetooth Audio SDK, tracked as CVE-2025-20701, affects Skullcandy Dime 3 earbuds running firmware 1.0.0.28, allowing nearby attackers to pair without user interaction. Once connected, an attacker can intercept audio, access the headset profile, and capture microphone input. Although Skullcandy released a fixed firmware version 1.0.0.30, users have no way to update their devices, leaving many units vulnerable.

Expanded Detail

The vulnerability was uncovered by ERNW researchers and presented at the TROOPER conference. It stems from a missing-authentication flaw in the Airoha Bluetooth Audio SDK, affecting multiple headphone brands. Airoha released SDK patches in August 2025, and Apple subsequently updated its Beats Studio Buds in June.

Once a rogue device pairs, it gains trusted status and can automatically reconnect, allowing attackers to seize audio playback and access the microphone. While Skullcandy issued firmware 1.0.0.30, CERT/CC confirms no consumer-accessible path exists to upgrade existing Dime 3 units from the vulnerable 1.0.0.28 version.

Context

This vulnerability could expose everyday consumers, particularly younger users drawn to the affordable Dime 3, to privacy invasions. An attacker within Bluetooth range may silently intercept private conversations or hijack music playback. The lack of a user-updatable firmware path means affected owners may remain exposed indefinitely. While the attack requires close physical proximity, the potential for covert microphone access could erode trust in consumer IoT devices, prompting users to reconsider the security of their personal audio gear.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
The Hidden Dangers of Always-On Bluetooth · Cybersecurity
Ransomware Gangs Join Attacks on Unpatched WatchGuard Fireboxes · Cybersecurity
Chrome Vulnerability Actively Exploited in the Wild Triggers Emergency Update · Cybersecurity
ConnectWise issues temporary workaround for unpatched ScreenConnect vulnerability · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking.” Browse more stories.