Wireless earbuds rarely appear on an organization's vulnerability dashboard, yet a warning concerning Skullcandy Dime 3 devices demonstrates why even inexpensive accessories require a credible security-update strategy. According to the disclosure, affected earbuds can accept pairing requests from a nearby, previously untrusted device without user interaction.
Pairing without permission
The problem is tracked as CVE-2025-20701 and affects Skullcandy Dime 3 model S2DCW earbuds running firmware version 1.0.0.28. It originates in the Airoha Bluetooth Audio software development kit used to provide wireless connectivity.
An attacker within Bluetooth range does not need a pairing PIN, physical access to the charging case or approval from the owner. After the unauthorized pairing succeeds, the attacker's device becomes trusted and may reconnect automatically when it returns to the area.
This access can be used to interrupt the legitimate connection, control audio playback, access headset functions and capture live microphone audio. The owner may hear a notification indicating that a new device has paired, but that warning could easily be mistaken for an ordinary connection problem.
A firmware fix users cannot install
Skullcandy reportedly corrected the vulnerability in firmware version 1.0.0.30. The more troubling issue is that consumers with devices running version 1.0.0.28 currently have no method to install the safe firmware manually or through the Skullcandy application.
In my view, a security patch that cannot reach deployed products is not a complete remediation. Connected-device manufacturers need update mechanisms that remain available throughout a product's supported life, along with clear tools for checking firmware versions and confirming installation.
Practical precautions
- Avoid using affected earbuds for confidential calls or sensitive voice communications.
- Pay attention to unexpected pairing alerts, connection interruptions or audio changes.
- Keep the earbuds powered down when they are not required, particularly in public locations.
- Organizations should include Bluetooth accessories in policies covering meetings, regulated conversations and secure facilities.
- Owners should monitor vendor communications for an official upgrade or replacement process.
The incident illustrates a broader Internet of Things problem. Security cannot end when a device leaves the factory. Vendors must provide a dependable path from vulnerability discovery to an update that customers can actually deploy.
