News

TechRadar warns cheap Skullcandy earbuds have a Bluetooth flaw that may let anyone connect

Carnegie Mellon University’s CERT Coordination Center disclosed on July 30, 2026, that Skullcandy’s Dime 3 wireless earbuds contain a Bluetooth vulnerability allowing unauthorized devices to connect without user consent. According to the report, the flaw exploits the earbuds’ firmware to accept pairing requests without requiring physical confirmation or pairing mode activation, potentially enabling attackers within Bluetooth range to access the device.

The vulnerability affects the Skullcandy Dime 3 wireless earbuds, model S2DCW, running firmware version 1.0.0.28, according to Carnegie Mellon University’s CERT Coordination Center (CERT/CC). CERT/CC publicly disclosed the issue on July 30, 2026, in Vulnerability Note VU#859658.

The flaw, tracked as CVE-2025-20701 and linked to the Airoha Bluetooth Audio SDK, allows the earbuds to accept Bluetooth Classic (BR/EDR) pairing requests from unpaired devices without requiring the earbuds to be in pairing mode or any physical confirmation from the user.

Technical analysis shows that the earbuds advertise an insecure BR/EDR pairing mode with NoInputNoOutput I/O capability, enabling zero-interaction pairing from nearby devices that have never connected before. Security testing demonstrated that a previously unknown Linux computer could establish a persistent Bluetooth bond with the earbuds without the owner’s intentional action, such as pressing buttons or opening the case. The attacker only needs to be within typical Bluetooth radio range, approximately 10 to 30 feet, to initiate an unauthorized pairing.

Once connected, the attacker’s device forms a persistent trusted bond stored on the earbuds, allowing automatic reconnection whenever the attacker is within range. This access enables the attacker to hijack audio playback through the Advanced Audio Distribution Profile (A2DP), disrupt or terminate the legitimate user’s Bluetooth connection, and control the audio stream. Additionally, because the attacker’s device gains access to headset and Hands-Free profiles, it may capture live microphone audio, potentially allowing eavesdropping on conversations through the earbuds, according to multiple security reports.

The vulnerability appears limited to firmware version 1.0.0.28. CERT/CC and other security write-ups emphasize that earlier or later firmware versions have not been confirmed as affected. The root cause is identified as missing authentication for Bluetooth BR/EDR pairing within the Airoha SDK implementation used in this firmware. The flaw differs from other Bluetooth Low Energy (BLE) vulnerabilities and is cataloged in public vulnerability databases, including Japan’s JVN iPedia, which cross-references the CERT/CC advisory.

CERT/CC’s advisory notes that exploiting the flaw requires no special tools or privileges beyond standard Bluetooth capabilities, raising concerns about opportunistic misuse in public spaces. The advisory highlights that the earbuds automatically accept pairing requests without user interaction, and victims receive only a spoken notification—“new device paired”—after the connection is already established. This notification does not provide an opportunity to approve or deny the pairing request, according to coverage by TechRadar and other consumer technology outlets.

TechRadar’s July 2026 report framed the issue as a significant security risk for budget earbud buyers, describing the Dime 3 as a “cheap” mass-market product rather than a niche or enterprise-grade device. Other consumer tech sites, including Techlicious, echoed these warnings, noting that an attacker standing nearby could connect to the earbuds silently and eavesdrop on audio without the owner’s knowledge until after the fact.

In response to the vulnerability, Airoha reportedly produced a patched Bluetooth Audio SDK, and the issue is considered fixed in firmware version 1.0.0.30 for affected devices, according to CERT/CC documentation and security briefings. However, as of mid-September 2026, no consumer-accessible method exists to upgrade existing Skullcandy Dime 3 units from the vulnerable 1.0.0.28 firmware to the patched version. The earbuds cannot receive firmware updates via the Skullcandy mobile app, effectively leaving already-sold units vulnerable unless replaced at the hardware level.

Security analysts categorize the flaw as a high-severity Bluetooth vulnerability because it violates standard Bluetooth SIG security expectations by allowing pairing and trusted connections without user consent. The attack requires minimal preconditions: no line-of-sight, no specialized hardware or malware, and no social engineering. The ability to capture live microphone audio through trusted headset profiles raises privacy concerns, as the earbuds could be exploited as ad-hoc listening devices in crowded or shared spaces.

The Skullcandy Dime 3 issue is part of a broader trend of Bluetooth vulnerabilities in consumer headphones and earbuds uncovered in 2025 and 2026. These vulnerabilities often involve missing authentication or insecure pairing workflows, enabling attackers within proximity to hijack audio streams or spy via microphones. Public vulnerability databases and national security repositories have internationally recognized and classified CVE-2025-20701 as an unauthenticated Bluetooth pairing vulnerability affecting consumer audio hardware.

CERT/CC continues to monitor the situation and encourages vendors to improve firmware update mechanisms to address such vulnerabilities. Meanwhile, security researchers and consumer reports highlight the importance of awareness regarding Bluetooth device security, especially in mass-market products with limited update capabilities.

.