Skullcandy Dime 3 wireless earbuds are vulnerable to a high-severity Bluetooth flaw that allows attackers to pair with the devices without user interaction, based on information published by Bleeping Computer.The vulnerability, tracked as CVE-2025-20701, affects firmware version 1.0.0.28 of the Skullcandy Dime 3 earbuds, which utilize the Airoha Bluetooth Audio SDK, the Carnegie Mellon University CERT Coordination Center (CERT/CC) warned. An attacker within close proximity can exploit this flaw to connect to the earbuds without a PIN, physical access, or an explicit pairing request. Once paired, the attacker's device becomes trusted, enabling automatic reconnection, interruption of the owner's connection, hijacking of audio playback, and access to the headset profile for capturing live microphone audio.While Skullcandy released a fix in firmware version 1.0.0.30, users with earlier firmware have no method to update their devices manually or through the Skullcandy application. This missing authentication vulnerability, discovered by ERNW researchers, affects a wide range of audio products, with Apple having previously addressed a similar flaw in its Beats Studio Buds. The inability for users to update vulnerable Skullcandy Dime 3 units poses a significant security risk, as there are no known consumer-accessible methods to upgrade to the safe firmware version.Source: Bleeping Computer
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
