bleeping-computer · Crawled Sep 10, 2026
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
2 IoCs
Read original article ↗
AI Summary
The Skullcandy Dime 3 wireless earbuds (model S2DCW) running firmware version 1.0.0.28 are vulnerable to Bluetooth hijacking due to a missing authentication flaw in the Airoha Bluetooth Audio SDK. This high-severity vulnerability, tracked as CVE-2025-20701, allows nearby attackers to pair with the device without user interaction or PIN confirmation. Once paired, the attacker's device becomes trusted and can automatically reconnect, enabling audio hijacking, microphone access, and connection disruption. Although Skullcandy released a fix in firmware version 1.0.0.30, there is no user-accessible method to update existing vulnerable units, leaving them permanently exposed.
AI-extracted · verify before operational use