Skullcandy Dime 3 Earbuds Vulnerable to Bluetooth Pairing Hijacking
CERT/CC warns of insecure pairing process allowing unauthorized device connections

Key Takeaways
- CERT/CC warns Skullcandy Dime 3 earbuds accept unauthorized Bluetooth pairing requests.
- No user interaction is required for a nearby device to pair with the earbuds.
- Potential for audio interception or manipulation by attackers in proximity.
- No firmware patch currently available to fix the pairing logic.
- Users should avoid pairing with unknown devices and monitor for firmware updates.
Quick answers
- What happened?
- The Carnegie Mellon University CERT Coordination Center (CERT/CC) has issued a warning regarding security flaws in the Skullcandy Dime 3 wireless earbuds. Research indicates the devices accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction, potentially enabling unauthorized access and audio hijacking.
- Which products are affected?
- Skullcandy Dime 3
- What should defenders do?
- Users should avoid pairing the Skullcandy Dime 3 with unknown or untrusted devices. Keep the earbuds' firmware updated for the latest security patches. CERT/CC and security researchers recommend monitoring official Skullcandy channels for a firmware update that addresses the pairing logic flaw.
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. This vulnerability could allow a nearby attacker to pair with the earbuds and potentially intercept or manipulate audio streams. The issue stems from the earbuds' Bluetooth pairing implementation, which does not enforce user confirmation for incoming pairing requests. Users within Bluetooth range of the devices could exploit this weakness to gain unauthorized access. Skullcandy has been notified of the findings. The advisory recommends that users keep the earbuds' firmware updated and avoid pairing with unknown devices. As of the advisory date, no firmware patch has been released to address the pairing logic flaw. The issue affects the Skullcandy Dime 3 model specifically. CERT/CC classifies the risk as significant due to the widespread use of wireless earbuds and the potential for privacy intrusion.
Security Details
The Skullcandy Dime 3 earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. This flaw allows potential unauthorized pairing and audio stream manipulation by attackers within Bluetooth range.
Affected products
Skullcandy Dime 3
Mitigation
Users should avoid pairing the Skullcandy Dime 3 with unknown or untrusted devices. Keep the earbuds' firmware updated for the latest security patches. CERT/CC and security researchers recommend monitoring official Skullcandy channels for a firmware update that addresses the pairing logic flaw.
Sources
BleepingComputer
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
Sep 9, 2026 · 21:02
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



