{
  "id": 7423362,
  "title": "These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device",
  "url": "https://urgent.news/2026/09/14/these-cheap-skullcandy-earbuds-have-a-worrying-bluetooth-flaw-that",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-14T23:10:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/these-cheap-skullcandy-earbuds-have-a-worrying-bluetooth-flaw-that-could-let-anyone-connect-to-your-device"
  },
  "original_language": "en",
  "account": "Carnegie Mellon University's CERT Coordination Center has reported that Skullcandy Dime 3 earbuds with older firmware versions are vulnerable to unauthorized Bluetooth pairing from unknown devices. This flaw allows anyone to connect to the earbuds without requiring any user interaction. The permanent connection can result in interrupted audio playback, hijacking of sound, and even capturing live microphone audio. A fix was released by Skullcandy in the form of firmware version 1.0.0.30, but this only applies to newly manufactured units. Users with older earbuds have no accessible method to upgrade their software, leaving them vulnerable to the issue. The underlying vulnerability, CVE-2025-20701, is not unique to Skullcandy and was disclosed by researchers from the German firm ERNW in June 2025. The severity of the issue varies between sources, with some assigning it a low rating and others a high categorization. While the vulnerability only affects the earbuds, an attacker could still manipulate the device to record conversations or pass hands-free commands to a paired smartphone.",
  "summary": "Apple can push a firmware fix to earbuds already in your pocket. Skullcandy cannot reach yours at all for now.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}