Overview
A newly disclosed vulnerability in Skullcandy Dime 3 wireless earbuds (model S2DCW) allows nearby attackers to pair without approval, hijack audio playback, and potentially capture live microphone audio. Tracked as VU#859658 and linked to CVE‑2025‑20701, the flaw stems from insecure Bluetooth Classic (BR/EDR) pairing behavior.
Vulnerability Details
- Unauthenticated pairing: Earbuds accept pairing requests even when not in pairing mode.
- No user interaction: Attackers don’t need PINs, passkeys, or button presses.
- Trusted device persistence: Once bonded, attacker devices reconnect automatically whenever nearby.
- Audio hijack: Attackers can take over sessions, play audio, or deny legitimate access.
- Microphone spying: Access to Hands‑Free or Headset profiles may expose live audio capture.
Root Cause
The flaw originates from Airoha Bluetooth audio SDK implementations. Because the earbuds use NoInputNoOutput I/O capability, pairing completes silently without owner confirmation.
Impact
- Attackers only need to be within Bluetooth radio range and know/discover the earbuds’ Bluetooth address.
- Victims hear a “New device paired” announcement only after unauthorized pairing succeeds.
- Ongoing risk: attacker devices remain trusted until manually removed.
Defensive Guidance
- Update firmware: Patch reportedly available in v1.0.0.30, but Dime 3 units don’t support consumer firmware updates.
- Avoid public use: Don’t use affected earbuds in crowded areas where attackers may be within range.
- Monitor pairing alerts: Stay alert for unexpected “New device paired” messages.
- Remove unknown devices: Regularly check paired‑device lists and delete suspicious entries.
Expert in the Cloud Insight
This flaw highlights how consumer audio devices can become surveillance tools when Bluetooth authentication is weak. Without firmware update support, Skullcandy Dime 3 owners face a persistent risk. The lesson is clear: Bluetooth security must be treated as seriously as network security—especially for devices with microphones.
Leave a Reply