Announcements
We ıntegrate ınformatıon ın lıfe

  • DOLAR
  • EURO
  • ALTIN
  • BIST
Critical Security Vulnerability Found in Cheap Bluetooth Headphones

Critical Security Vulnerability Found in Cheap Bluetooth Headphones

The critical Bluetooth vulnerability in Skullcandy Dime 3 headphones causes unauthorized pairing of devices. No update path found.

The Skullcandy Dime 3 vulnerability poses a significant risk to wireless headphone users. The CERT Coordination Center at Carnegie Mellon University announced that these devices can pair with unfamiliar devices without user consent.

This can lead to the interruption of communication and the interference of playing content. After pairing, the device only provides an audible notification indicating that a new device has been paired.

This security flaw also allows access to the headphones’ microphone. This enables attackers to record live audio without the users’ knowledge.

Technical Details of the Vulnerability

This vulnerability, identified as CVE-2025-20701, is not actually a software bug directly created by Skullcandy. The problem stems from Bluetooth system chips manufactured by Taiwan-based Airoha.

Dennis Heinze and Frieder Steinmetz from ERNW declared this vulnerability at the TROOPERS conference in Heidelberg in June 2025. Although Airoha released an SDK update for this vulnerability in June 2025, the situation is different for Dime 3 owners.

Different institutions have different assessments of the vulnerability’s severity. MediaTek gave the vulnerability a score of 6.7, while CISA’s vulnerability enrichment program placed it in the high category with a score of 8.8.

Independent researcher Jacob Nowak shared these findings on the Full Disclosure mailing list in early August. Nowak confirmed the vulnerability in tests he conducted on his own hardware.

Lack of Update Method and User Risk

Skullcandy has released a patch, version 1.0.0.30, for devices using version 1.0.0.28. However, this update is only available on newly manufactured headphones.

There is no way for existing users to update their devices. The lack of a supporting application for the headphones means this vulnerability persists on existing devices.

For an attacker to exploit this vulnerability, they need to be within a few meters of the victim. In more advanced scenarios requiring technical skill, risks such as accessing the phonebook or viewing the invitation history through the headphones are theoretically possible.

This creates a scenario where users do not have full control over their own devices. What are your thoughts on this vulnerability?

Social Media Share:

TOGETHER FOR A LOOK

Can you share with us your comment?