CISA flags unauthenticated Bluetooth Classic pairing issue in Skullcandy Dime 3
47th article in the last 90 days, one of 601 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: CISA issues guidance on UEFI Shell Secure Boot bypass (Sep 2026).
Companies mentioned
Best suited for
- Job function
- Chief Information Security Officer
- Seniority
- C Level / Executive Team
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Adopters
- Technology maturity
- Market Correction
- Industry
- Information Technology / Software & Services / Cybersecurity / Governance, Risk & Compliance (GRC) & Security Ratings
Our classification, not the publisher's statement. Best suited for, not only for.
Skullcandy Dime 3 wireless earbuds with firmware version 1.0.0.28 have an unauthenticated Bluetooth Classic (BR/EDR) pairing vulnerability that can result in remote escalation of privilege and automatic bonding with an added device.
The Skullcandy Dime 3 (Model S2DCW) earbuds accept a Bluetooth Classic (BR/EDR) pairing request from a previously unpaired device without the device being placed into pairing mode by the owner and without physical confirmation on the earbuds. The earbuds’ Bluetooth PnP modalias identifies the chipset vendor as Airoha Technology Corp. (Bluetooth SIG company ID 0x0094). This issue was previously disclosed as CVE-2025-20701. The described condition is that in the Airoha Bluetooth audio SDK, a way exists to pair a Bluetooth audio device without user consent, which could lead to remote escalation of privilege with no additional execution privileges needed, and user interaction is not needed for exploitation. An attacker must be within Bluetooth radio range, but no prior pairing, physical access, or interaction with the earbuds’ buttons or case is required. A direct pairing request to the earbuds’ known or discovered Bluetooth Classic address can be sent without a PIN, passkey, or physical confirmation, and pairing/bonding completes without owner action due to the device’s NoInputNoOutput I/O capability. The firmware version displayed is 1.0.0.28.
After bonding, the attacker’s device is added as a trusted device and can reconnect automatically whenever in range. The attacker can establish an A2DP audio transport that interrupts the legitimate user’s active connection to their own device. The only indication to the legitimate user is an audible “New device paired” notification, given after unauthorized pairing has succeeded, with no opportunity to block it in advance. Depending on device capabilities, the issue could allow an attacker to hijack the audio session or access other services exposed over the same Bluetooth Classic connection. The attacker can also access the Dime 3’s Hands-Free/Headset profile and capture live microphone audio.
The vendor considers the CVE-2025-20701 patch in firmware version 1.0.0.30 to be effective. Skullcandy confirmed that the Dime 3 does not support firmware updates through the Skullcandy application, and existing units running firmware 1.0.0.28 cannot currently be updated by customers through the app. As of the writing date, there are no known consumer-accessible methods to update an existing unit from version 1.0.0.28 to version 1.0.0.30.
In the advisory material, the vulnerability is attributed to CVE-2025-20701 and described in terms of pairing Bluetooth audio devices without user consent. The document states that exploitation does not require user interaction and requires the attacker to be within Bluetooth radio range, with no prior pairing, physical access, or interaction with the earbuds’ buttons or case. It also notes that pairing/bonding completes without owner action due to the device’s NoInputNoOutput I/O capability.
Blog post, originally published by Bob Kemerer at kb.cert.org.