Skullcandy Earbud Flaw Exposes Microphones To Remote Attackers

https://images.hothardware.com/contentimages/newsitem/71590/content/16x9_2133x1200_highres-dime3-case.jpg

A security flaw in Skullcandy's Dime 3 wireless earphones allows nearby attackers to hijack Bluetooth connections, intercept audio playback, and access built-in microphones without any user interaction or physical confirmation.

To be specific, the vulnerability affects Dime 3s running firmware version 1.0.0.28. The bug stems from an unauthenticated Bluetooth pairing flaw tracked as CVE-2025-20701, which resides within the underlying Airoha Bluetooth Audio SDK used by the manufacturer. Originally presented by cybersecurity researchers at ERNW, the underlying flaw represents a missing-authentication issue in the Bluetooth stack that allows incoming connection requests to complete automatically without user consent.

A vulnerability advisory issued by the Carnegie Mellon University CERT Coordination Center (CERT/CC), initiated after a tip from researcher Jacob Nowak, warns that an attacker within wireless radio range can initiate a Bluetooth Classic request to a pair of Dime 3s. Because the buds employ a "NoInputNoOutput" I/O profile, the Bluetooth stack accepts incoming...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE