Skullcandy Dime 3 earbuds let strangers pair over Bluetooth with no PIN, and owners can't patch them
A flaw in the Airoha chip inside Skullcandy's popular Dime 3 earbuds lets anyone nearby connect silently and listen through the microphone. Skullcandy has a fix, but no way for customers to install it.

Key points
- Skullcandy Dime 3 earbuds (model S2DCW) running firmware 1.0.0.28 accept Bluetooth pairing from strangers without any approval or PIN.
- The flaw is CVE-2025-20701, a missing-authentication bug in the Airoha Bluetooth Audio SDK used by many earbud brands.
- Once paired, an attacker within Bluetooth range can hijack audio and capture live microphone sound from the earbuds.
- Skullcandy fixed the flaw in firmware 1.0.0.30, but the Skullcandy app offers no way for owners to update.
- Carnegie Mellon's CERT/CC published the advisory after a tip from researcher Jacob Nowak.
Skullcandy's Dime 3 wireless earbuds, a cheap and popular set aimed at younger buyers, will pair with any Bluetooth device nearby without asking the owner first. That is according to a new advisory from the CERT Coordination Center (CERT/CC) at Carnegie Mellon University, first reported by BleepingComputer.
The problem sits in a chip supplied by Airoha, a Taiwanese company whose Bluetooth Audio software development kit (SDK), the pre-built code manufacturers drop into their products to handle wireless audio, is used inside earbuds and headphones from many brands. In the Dime 3, that SDK skips a basic check: it does not confirm the owner actually wants a new device to connect.
What can an attacker actually do?
Someone within Bluetooth range, roughly the width of a coffee shop, can silently pair their phone or laptop to your earbuds. No PIN. No pop-up asking you to approve it. No need to open the charging case.
Once paired, the attacker's device is treated as trusted. It can reconnect automatically whenever it is nearby, cut into your audio, play its own sound through your earbuds, and switch on the headset profile to record what the earbud microphone picks up. That includes your side of any conversation happening near you.
You might hear a brief "new device paired" chime, but most people will shrug it off as a glitch.
Which product and firmware are affected?
| Item | Detail |
|---|---|
| Product | Skullcandy Dime 3 (model S2DCW) |
| Vulnerable firmware | 1.0.0.28 |
| Fixed firmware | 1.0.0.30 |
| CVE | CVE-2025-20701 |
| Airoha SDK patch released | 4 August 2025 |
The bug was found by researchers at German security firm ERNW and presented at the TROOPERS conference last year. It affects a wide range of Airoha-based audio products, not just Skullcandy. Apple, for example, pushed a fix for its Beats Studio Buds in June.
Why can't owners just update?
Because Skullcandy has not built an update path into its app. CERT/CC's advisory is blunt: "Existing units running the vulnerable firmware cannot currently be updated by customers through the app... there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30."
So the fix exists, but it only helps units that shipped with the newer firmware already installed. Anyone who bought a Dime 3 earlier is stuck.
Skullcandy has not responded publicly. Its customer support runs through a chatbot that does not accept press queries.
What should Dime 3 owners do?
Until Skullcandy offers a real update route, the safest option is to treat the earbuds as untrusted in any private setting. A few practical steps:
- Check your firmware version in the Skullcandy app. If it reads 1.0.0.28, you are affected.
- Keep the earbuds in their case when you are not actively using them. A closed case with the buds powered down cannot be paired to.
- Avoid wearing them during sensitive conversations, medical appointments, banking calls, or work meetings you would not want a stranger to hear.
- Watch your paired-devices list on your phone. If an unfamiliar device appears, unpair it and factory-reset the earbuds.
Consumer electronics rarely fall under a single privacy regulator, but in the United States the Federal Trade Commission (FTC) has previously taken action against manufacturers who ship products with unfixable security defects. In the UK, the Product Security and Telecommunications Infrastructure (PSTI) regime now requires connected consumer devices to support security updates for a defined period, which is exactly the gap on display here.



