Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
CERT/CC warns Skullcandy Dime 3 earbuds are vulnerable to Bluetooth hijacking due to a high-severity vulnerability in their firmware.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers warn of a Bluetooth security flaw in Skullcandy Dime 3 earbuds, exposing users to potential hijacking.
This is like if someone could secretly listen in on your phone calls without you knowing. The earbuds have a problem that lets bad guys connect to them and listen in, even if you don't know they're there.
Analysis
{"heading_1":"The Vulnerability","paragraph_1":"Existing units running the vulnerable firmware cannot currently be updated by customers through the app, leaving users at risk of potential hijacking.","paragraph_2":"To prevent this vulnerability, users should ensure their firmware is up to date and avoid pairing with unknown devices to minimize the risk of unauthorized access.","paragraph_3":"Security researchers recommend that users who have older firmware versions should contact Skullcandy for assistance in upgrading to a safe version.","heading_2":"The Impact","heading_3":"Prevention and Mitigation","paragraph_4":"The CERT/CC advises users to be cautious when pairing devices and to monitor their audio communications for any unauthorized access or interruptions."}
Key points
- Skullcandy Dime 3 earbuds are vulnerable to Bluetooth hijacking due to a missing-authentication problem in their firmware.
- Users who bought the earbuds with an earlier firmware release have no way to upgrade to a safe version.
- Users should ensure their firmware is up to date and avoid pairing with unknown devices to minimize the risk of unauthorized access.
- The vulnerability affects devices running firmware version 1.0.0.28 and is caused by a high-severity missing-authentication problem in the Airoha Bluetooth Audio SDK.
- The vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.
Users can stay safe by keeping their firmware up to date and avoiding pairing with unknown devices.
If users don't update their firmware, bad guys could still listen in on their calls, even if they're not aware of it.


