These Earbuds Pair With Strangers Without Asking, and the Microphone Comes With Them
Skullcandy Dime 3 earbuds running firmware 1.0.0.28 can accept a new Bluetooth pairing from a stranger without being placed into pairing mode and without any confirmation from the owner. Once trusted, the attacker's device can interrupt the owner's audio and use the headset profile to capture live microphone audio. A fixed firmware exists, but CERT/CC says affected consumers currently have no way to install it.
The attack requires the person to be within Bluetooth radio range. It does not require prior pairing, physical access to the earbuds, a button press, a PIN or a passkey. The only warning is an audible "New device paired" message after the unauthorised pairing has already succeeded.
CERT/CC published the finding on 8 September 2026 as Vulnerability Note VU#859658. The note maps the issue to CVE-2025-20701, a previously disclosed weakness in the Airoha Bluetooth audio software development kit.
The confirmed product scope is narrow: Skullcandy Dime 3, model S2DCW, on firmware 1.0.0.28. The advisory does not establish that every Skullcandy product, every Airoha-based device or Bluetooth earbuds generally behave in the same way. There is no evidence in the primary source of exploitation in the wild.
Pairing succeeds before the owner can object
Bluetooth devices normally use pairing mode or an owner-confirmation step to decide when a new controller is allowed to become trusted. The affected Dime 3 firmware accepts a direct Bluetooth Classic, also called BR/EDR, pairing request from a previously unpaired device without either boundary.
CERT/CC says an attacker can send the request to a known or discovered Bluetooth address. Pairing completes without a PIN, passkey or physical confirmation because the earbuds present a NoInputNoOutput input-output capability.
That capability is common for devices that do not have a keyboard or screen. It does not, by itself, make every such device vulnerable. The failure here is that the earbuds accept a new bond while they are not intentionally in pairing mode and the owner has not authorised the relationship.
Once bonding completes, the attacker's device is stored as trusted and can reconnect automatically whenever it returns to range.
The impact reaches both audio directions
CERT/CC describes two immediate consequences.
First, the attacker can establish an Advanced Audio Distribution Profile connection of its own. That can interrupt or displace the legitimate user's active audio connection. The owner may hear the post-pairing notification, but it arrives too late to block the new bond.
Second, the attacker can access the Hands-Free or Headset profile and capture live microphone audio. That turns a pairing-control failure into a privacy issue. Earbuds may be worn during calls, work conversations or ordinary activity, and the microphone is designed to remain close to the user.
The advisory also says other services exposed over the same Bluetooth Classic connection could potentially be accessible, depending on device capabilities. That is a possibility identified by CERT/CC, not proof that additional Dime 3 services have been exploited.
The finding does not give a nearby attacker access to the paired phone as a whole. It demonstrates unauthorised trust on the earbuds and access to the audio profiles the earbuds expose.
The patch exists, but the update path does not
CERT/CC says Skullcandy considers firmware 1.0.0.30 to contain an effective correction for CVE-2025-20701. The consumer problem is delivery.
The Dime 3 does not support firmware updates through the Skullcandy application. As of the 8 September advisory, CERT/CC knew of no consumer-accessible method for moving an existing unit from vulnerable firmware 1.0.0.28 to fixed firmware 1.0.0.30.
That creates a familiar connected-device failure. A manufacturer can correct code used in new production while devices already in customers' hands remain on the vulnerable build. A patch without a supported distribution path does not remediate the installed base.
The vulnerability note lists the vendor status as unknown and says CERT/CC had not received a formal vendor statement for publication. The confirmation about firmware 1.0.0.30 is reported by CERT/CC in its solution section.
What Dime 3 owners can do now
There is no complete consumer mitigation in the advisory. The following steps can reduce exposure or help identify suspicious pairing, but they do not install the fix:
- Check the exact model and firmware. The confirmed finding concerns Skullcandy Dime 3 model S2DCW running firmware 1.0.0.28.
- Treat an unexpected pairing announcement as a security event. Stop using the earbuds for sensitive calls and inspect the Bluetooth connections on devices in range.
- Power the earbuds off when they are not needed. An unavailable radio cannot accept a nearby pairing request.
- Avoid sensitive use in crowded or hostile locations. Bluetooth range is limited, but offices, public transport, conferences and shared accommodation can place unknown devices close enough to try.
- Monitor Skullcandy and CERT/CC guidance. A consumer update or replacement route may become available after publication.
- Follow a supported remediation route if one becomes available. Use only a vendor-provided reset, update or replacement process that Skullcandy or CERT/CC confirms addresses the stored unauthorised bond.
Organisations that issue consumer audio devices for work should identify affected units and decide whether they are appropriate for meetings involving sensitive information. A procurement control should also ask a basic lifecycle question before deployment: can fielded devices receive authenticated security updates?
Why this is more than an annoying Bluetooth takeover
An attacker playing audio through someone else's earbuds is disruptive. The more serious boundary is the microphone.
The device has no screen on which to show a new trusted identity and no meaningful opportunity for the owner to reject it. Its audible message reports that pairing has happened rather than asking whether it should happen. That is notification after authorisation, not authorisation itself.
BlackTree previously covered a Unitree robot whose Bluetooth path could lead to root access. The affected products and consequences are very different, but the design lesson is similar. Proximity is a prerequisite, not consent. A nearby radio should not be able to create a durable trust relationship simply because the device lacks buttons or a display.
The Dime 3 case also shows why updateability belongs in the security specification for inexpensive connected hardware. The fixed firmware proves that the behaviour can be corrected. The missing consumer delivery route determines whether owners can benefit from that correction.
Until that changes, affected users are left managing proximity and listening for a warning that arrives after the trust boundary has already failed.
Sources
- CERT/CC Vulnerability Note VU#859658, initially released 8 September 2026 with no initial time provided; last updated 8 September 2026 at 14:42 UTC.
- NVD vulnerability record.


