· · Single source ·Updated

Skullcandy Dime 3 earbuds have a Bluetooth flaw allowing unknown devices to pair

Carnegie Mellon University researchers warn that Skullcandy Dime 3 wireless earbuds on older firmware accept Bluetooth pairing requests from strangers without user interaction.

These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device
File photo These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device Photo: TechRadar

Vulnerability allows unauthorized device connection

The vulnerability lets an attacker interrupt the owner's connections and hijack audio playback. Researchers state that the earbuds can also capture live microphone audio once paired with a malicious device. This pairing happens automatically without any confirmation from the user.

Fix available only for new units

A firmware update patches the issue but is only available on newer hardware. Skullcandy has addressed the problem for earbuds running version 1.0.0.28, yet existing devices cannot receive this fix. The advisory credits independent researcher Jacob Nowak for identifying the flaw in early August.

Reported by one outlet

Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.

Reported by

1 independent outlet. Headline as published. Links open the original report.