[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Skullcandy Dime 3 unauthorized Bluetooth pairing behavior
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Skullcandy Dime 3 unauthorized Bluetooth pairing behavior
- From: Jacob Nowak <jacobnowak15@xxxxxxxxx>
- Date: Tue, 28 Jul 2026 14:00:34 -0600
Hello,
I am submitting the following security disclosure for publication on the
Full Disclosure mailing list.
Title: Pairing Without Consent: CVE-2025-20701 Behavior on Skullcandy Dime 3
Affected product:
Skullcandy Dime 3 wireless earbuds
Vulnerability:
Unauthorized Bluetooth Classic pairing and persistent bond creation
Description:
Testing demonstrated that a previously unknown Linux computer could pair
with a Skullcandy Dime 3 earbud set and store a persistent Bluetooth bond
without the earbuds being intentionally placed into pairing mode.
No confirmation or physical interaction with the earbuds was required
during the pairing process.
The observed behavior is consistent with CVE-2025-20701.
Security impact:
A nearby attacker within Bluetooth range may be able to establish an
unauthorized trusted relationship with the earbuds. The stored bond could
allow subsequent connections from the unauthorized device and potentially
interfere with the legitimate user’s Bluetooth connection.
Evidence:
The public research repository includes:
- A detailed technical report
- Reproduction information
- Screenshots
- A sanitized BTSnoop capture
- A packet-level description of the pairing sequence
Repository:
https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701
The published BTSnoop capture preserves the pairing and connection
sequence. The 16-byte BR/EDR link key was replaced with zero bytes before
publication. The original, unmodified capture has been retained privately.
This research was conducted on hardware I own and is being published for
defensive research, independent verification, and vendor awareness.
Regards,
Jacob Nowak
Independent Security Researcher
GitHub: https://github.com/x0jac0b0x
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/