Skullcandy Dime 3 earbuds have a Bluetooth flaw allowing unknown devices to pair
Carnegie Mellon University researchers warn that Skullcandy Dime 3 wireless earbuds on older firmware accept Bluetooth pairing requests from strangers without user interaction.

Vulnerability allows unauthorized device connection
The vulnerability lets an attacker interrupt the owner's connections and hijack audio playback. Researchers state that the earbuds can also capture live microphone audio once paired with a malicious device. This pairing happens automatically without any confirmation from the user.
Fix available only for new units
A firmware update patches the issue but is only available on newer hardware. Skullcandy has addressed the problem for earbuds running version 1.0.0.28, yet existing devices cannot receive this fix. The advisory credits independent researcher Jacob Nowak for identifying the flaw in early August.
Reported by one outlet
Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.
Reported by
1 independent outlet. Headline as published. Links open the original report.