CERT/CC warned that Skullcandy Dime 3 wireless earbuds, model S2DCW, running firmware 1.0.0.28 are vulnerable to CVE-2025-20701, a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK. An attacker within Bluetooth range can pair with the earbuds without a PIN, user approval, or physical access, then reconnect as a trusted device to interrupt or hijack audio, access headset functions, and potentially capture live microphone audio.
Skullcandy remediated the flaw in firmware 1.0.0.30, but owners of already-sold vulnerable units reportedly have no consumer-accessible update path, including through the Skullcandy app. The Airoha SDK issue affects audio devices from multiple vendors; Airoha released SDK updates in August 2025, while Apple issued a firmware fix for affected Beats Studio Buds.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Airoha published SDK updates intended to address CVE-2025-20701.
CERT/CC reported that Dime 3 model S2DCW earbuds running firmware 1.0.0.28 accept nearby pairing requests without user interaction, a PIN, or physical access. An unauthorized device can become trusted and reconnect to interrupt audio, access the headset profile, or capture live microphone audio.
Skullcandy remediated CVE-2025-20701 in Dime 3 firmware version 1.0.0.30. Owners of already-sold units running vulnerable version 1.0.0.28 reportedly have no consumer-accessible method, including the Skullcandy app, to install the update.
Apple addressed CVE-2025-20701 in Beats Studio Buds through a firmware update. The references conflict on whether that update was released in June 2025 or June 2026.
ERNW researchers discovered CVE-2025-20701, a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK, and presented the issue at the TROOPERS cybersecurity conference. The flaw affects Bluetooth audio products from multiple vendors using the SDK.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcemkd-cirt.mk
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.