Skullcandy Dime 3 unauthorized Bluetooth pairing behavior
Jacob Nowak ·
Hello, I am submitting the following security disclosure for publication on the Full Disclosure mailing list. Title: Pairing Without Consent: CVE-2025-20701 Behavior on Skullcandy Dime 3 Affected product: Skullcandy Dime 3 wireless earbuds Vulnerability: Unauthorized Bluetooth Classic pairing and persistent bond creation Description: Testing demonstrated that a previously unknown Linux computer could pair with a Skullcandy Dime 3 earbud set and store a persistent Bluetooth bond without the earbuds being intentionally placed into pairing mode. No confirmation or physical interaction with the earbuds was required during the pairing process. The observed behavior is consistent with CVE-2025-20701. Security impact: A nearby attacker within Bluetooth range may be able to establish an unauthorized trusted relationship with the earbuds. The stored bond could allow subsequent connections from the unauthorized device and potentially interfere with the legitimate user’s Bluetooth connection. Evidence: The public research repository includes: - A detailed technical report - Reproduction information - Screenshots - A sanitized BTSnoop capture - A packet-level description of the pairing sequence Repository: https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701 The published BTSnoop capture preserves the pairing and connection sequence. The 16-byte BR/EDR link key was replaced with zero bytes before publication. The original, unmodified capture has been retained privately. This research was conducted on hardware I own and is being published for defensive research, independent verification, and vendor awareness. Regards, Jacob Nowak Independent Security Researcher GitHub: https://github.com/x0jac0b0x _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/