WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

Analyst seen from behind facing a wall of blurred monitoring screensAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

This vulnerability was previously disclosed in CVE-2025-20701 and is described as: In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. Impact Once bonded, the attacker's device is added as a trusted device and can reconnect automatically whenever in range.

An attacker is required to be within Bluetooth radio range to the target earbuds, but no prior pairing, physical access, or interaction with the earbuds' buttons or case is required to exploit the vulnerability. The firmware version displayed on the affected Skullcandy Dime 3 wireless earbuds is 1.0.0.28.

This allows an attacker to establish an A2DP audio transport, which interrupts the legitimate user's active connection to their own device. The only indication to the legitimate user is an audible "New device paired" notification, given after the unauthorized pairing has already succeeded, providing no opportunity to block it in advance.

Sources & evidence