Thursday, 8 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed
Technology

These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device

TechRadar ·
These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device

Researchers warn Skullcandy Dime 3 earbuds on older firmware accept Bluetooth pairing from unknown devices with no user interaction required When leveraged, it can be used to interrupt the owner's connections, hijack playback, and even capture live microphone audio The vulnerability has been patched in a newer firmware update available only on newer units, does not seem to be addressable for existing earbuds Carnegie Mellon University's CERT Coordination Center has warned Skullcandy's Dime 3 wireless earbuds will accept a Bluetooth pairing request from a stranger's device without the owner doing anything.

The resulting bond is permanent, and the only sign the owner gets is a spoken "new device paired" notification delivered after it has already happened, with zero user interaction to confirm the request.

The advisory covering the Dime 3 was written by CERT/CC's Bob Kemerer and credits independent researcher Jacob Nowak, who had posted his findings to the Full Disclosure mailing list in early August after testing it on hardware he owned.

A fix deployed that covers virtually no existing users What makes this worse is that, ironically, while Skullcandy was swift in addressing the issue affecting earbuds running firmware version 1.0.0.28 by rolling out a patched version 1.0.0.30, it seems to address the issue only in newly made units.

CERT notes that there seem to be no "consumer-accessible" methods to upgrade existing units to the newest firmware because it reportedly has no support via the companion app, as a Tom's Guide review indicates .

A product without an update path that is user-accessible essentially means that its software flaws, or in this case, security issues, are here to stay for users who have had the bad luck of buying an earlier unit.

The underlying vulnerability, CVE-2025-20701, is not new and is not of Skullcandy's making.

It is one of three vulnerabilities that Dennis Heinze and Frieder Steinmetz of the German firm ERNW disclosed in June 2025 at the TROOPERS conference in Heidelberg, affecting Bluetooth systems-on-chip from Taiwan's Airoha.

The Dime 3's Bluetooth identifier names Airoha as its chipset vendor, and while Airoha shipped a fixed SDK to its customers in June 2025 and published its bulletin that August, owners of the earbuds are in a unique situation, to say the least.

The vulnerability's severity is disputed: MediaTek (which owns Airoha) assigned it a relatively low 6.7 rating, while CISA's vulnerability enrichment program later assigned it an 8.8 with a 'high' categorization .

A potential attacker is limited to what the earbuds can access, since the vulnerability is essentially limited to the earbuds, but one could still wreak havoc with that alone.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›