Bluetooth bug in Skullcandy Dime 3 earbuds permits unauthorized pairing
A team of security researchers uncovered a serious Bluetooth flaw in Skullcandy’s Dime 3 true‑wireless earbuds, which can let any device in proximity link to them without the owner’s consent. The defect resides in legacy firmware and operates without any user action, enabling an attacker to pair with the earbuds unnoticed.
The problem surfaced while researchers performed a standard review of consumer audio gear. In discoverable mode the earbuds automatically accept pairing attempts from unfamiliar devices. After a successful link, an intruder can interfere with the user’s current Bluetooth links, commandeer music playback, and even trigger the built‑in microphone to record ambient sound.
Normally, Bluetooth pairing requires the user to approve a code or connection prompt. The Dime 3 earbuds sidestep this safeguard, violating a core security assumption for wireless accessories. Analysts caution that the vulnerability could be abused in venues like gyms, cafés or public transit, where users often leave their earbuds active and within striking distance of attackers.
Skullcandy has not released an official comment, though it has previously rolled out firmware patches to fix security issues across its range. Owners should consult the Skullcandy app or the support website for any pending updates and apply them without delay. Turning off the earbuds’ Bluetooth when they’re idle and disabling any automatic‑pairing option, where available, can further limit risk.
This finding underscores a wider problem in the fast‑growing sector of low‑cost true‑wireless earbuds. Producers frequently favor price and ease of use over thorough security vetting, exposing users to attacks that previously affected only more sophisticated hardware. Experts observe that as earbuds gain functions like voice‑assistant integration and health monitoring, they become increasingly attractive targets for malicious actors.
Security professionals advise users to handle earbuds the same way they would any connected gadget: maintain up‑to‑date firmware, steer clear of untrusted settings, and watch for odd signs such as unsolicited audio or rapid battery loss. Until Skullcandy delivers a fix, listeners should stay vigilant and may wish to switch to headphones that require clear pairing approval.
Comments (0)
Be the first to comment.
Join the discussion