News

    Critical Security Flaw Found in Skullcandy Dime 3 Bluetooth Headphones

    A critical security vulnerability in Skullcandy Dime 3 Bluetooth headphones allows unauthorized pairing and microphone access. Learn why there is no fix for existing users.

    A severe security vulnerability has been identified in the Skullcandy Dime 3, posing a significant risk to users of these popular wireless headphones. According to a report by the Carnegie Mellon University CERT Coordination Center, the device suffers from a flaw that permits unauthorized third-party devices to pair with the headphones without requiring user consent. This security oversight allows attackers to disconnect current users and intercept audio streams. Furthermore, the vulnerability grants unauthorized access to the built-in microphone, potentially enabling malicious actors to record private conversations without the owner’s knowledge or approval.

    • The security flaw allows unauthorized third-party devices to pair with headphones without user intervention.
    • Attackers can potentially access the microphone to record audio without the victim’s awareness.
    • The underlying issue originates from Airoha-manufactured Bluetooth system-on-chips rather than Skullcandy’s specific software.
    • Existing users have no mechanism to patch their devices, as the update is limited to new factory units.

    Technical Origins Reveal Chipset Vulnerability

    The technical root of this issue, designated as CVE-2025-20701, is not a direct flaw in Skullcandy’s own code but stems from the Bluetooth system-on-chips produced by the Taiwanese company Airoha. Security researchers Dennis Heinze and Frieder Steinmetz from ERNW first disclosed the existence of this vulnerability during the TROOPERS conference in Heidelberg in June 2025.

    While Airoha released an SDK update shortly thereafter to address the flaw at the manufacturing level, this solution does not retroactively protect devices already in the hands of consumers.

    Risk Assessments Vary Among Security Agencies

    The severity of this vulnerability has triggered varying responses from cybersecurity organizations. MediaTek has assigned the flaw a risk score of 6.7, while the Cybersecurity and Infrastructure Security Agency (CISA) has classified it as a high-risk threat with a score of 8.8. Independent researcher Jacob Nowak further validated these findings in August 2025, providing evidence from his own hardware testing that confirmed the ease with which these headphones can be hijacked by unauthorized signals.

    Update Limitations Leave Users Exposed

    Skullcandy has developed a firmware patch, version 1.0.0.30, intended to rectify the issue for units currently using version 1.0.0.28. However, this fix is exclusively integrated into newly manufactured production batches. Because the current Skullcandy Dime 3 units lack support for a companion mobile application or an end-user update interface, the vulnerability remains permanent for existing owners. To exploit this flaw, an attacker must typically be located within a few meters of the target, but the potential consequences include unauthorized access to call histories and contact information in more advanced exploitation scenarios. This situation highlights a critical gap in consumer hardware security where users lack the tools to remediate known risks.

    Given that there is no way to update these devices, are you concerned about the longevity and security of your wireless gadgets, or does this change how you view budget-friendly electronics? Please share your thoughts in the comments section below.

    No comments yet Write the First Comment
    ×

    Your comment has been submitted,
    it will be published after approval.

    Write a Comment