Vulnerability
Published 2026-09-09
Verified 2026-09-19

Skullcandy Dime 3: Bluetooth pairing without user consent (CVE-2025-20701)

CERT/CC and BleepingComputer (9 September 2026) warn that Skullcandy Dime 3 earbuds (model S2DCW) on firmware 1.0.0.28 accept Bluetooth pairing from nearby unpaired devices without user interaction, PIN, or case access. Issue tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK. Skullcandy says fixed in firmware 1.0.0.30, but end users have no supported update path via the Skullcandy app. Nearby attacker can hijack the audio link. Broader Airoha-based headset class affected per ERNW/TROOPERS research. Primary wire: BleepingComputer citing CERT/CC.

Product
Skullcandy Dime 3 (S2DCW) / Airoha Bluetooth Audio SDK
Versions
Affected firmware 1.0.0.28; vendor says fixed in 1.0.0.30 (no user update path reported)
Exploited in Australia?
unknown
Patch to
No consumer OTA path reported; treat as unpatchable in field — physical proximity risk; prefer devices with updateable firmware

Primary: BleepingComputer — Skullcandy Dime 3 (9 Sep 2026) · CVE: CVE-2025-20701

vulnerabilities network