Skullcandy Dime 3 Earbuds Bluetooth Flaw Poses Persistent Security Risk

Skullcandy Dime 3 earbuds accept unauthorized Bluetooth pairing without user consent, enabling interception of audio and playback control. Firmware fixes apply only to new units, leaving existing users vulnerable.

Skullcandy Dime 3 Earbuds Bluetooth Flaw Poses Persistent Security Risk
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is the Bluetooth vulnerability in Skullcandy Dime 3 earbuds?

Skullcandy Dime 3 wireless earbuds have a Bluetooth security flaw that allows unknown devices to pair permanently without any user interaction or explicit approval. After unauthorized pairing, the earbuds announce a "new device paired" notice, but this alert occurs only after the connection is established, providing minimal warning.

This flaw means an attacker within Bluetooth range can connect to the earbuds stealthily, disrupting the owner's audio experience, hijacking playback, or potentially using the earbuds' microphone to listen to surrounding conversations.

Who is affected and how severe is the risk?

Skullcandy Dime 3 True Wireless Earbuds | Multipoint Bluetooth Pairing,  20-Hour Battery Life, Built-in Mic, Auto Connect | Compatible with iPhone &  Android – Black : Amazon.in: Electronics
Skullcandy Dime 3 True Wireless Earbuds | Multipoint Bluetooth Pairing, 20-Hour Battery Life, Built-in Mic, Auto Connect | Compatible with iPhone & Android – Black : Amazon.in: Electronics

The vulnerability affects Dime 3 earbuds shipped with an older firmware version (1.0.0.28 or earlier). It does not apply to new units that come with the updated firmware (1.0.0.30). The issue stems from a known vulnerability in the Airoha Bluetooth chipset integrated into these earbuds.

While some industry assessments rate the vulnerability as moderate, others classify it as high risk due to the potential for sensitive audio interception and control over playback that could be exploited in various malicious ways. However, exploiting the flaw beyond basic disruption requires close proximity, technical expertise, and additional conditions such as a connected smartphone with Bluetooth enabled.

Why can't existing users patch their earbuds?

Although Skullcandy released a firmware update addressing the flaw, it appears only newly manufactured Dime 3 earbuds come preloaded with the fixed firmware. There is no accessible method for consumers to update older units themselves, as the companion app does not support firmware upgrades for these earbuds.

This lack of an update path means that users with older earbuds remain exposed to the vulnerability indefinitely, unless Skullcandy provides a user-friendly firmware upgrade option. This contrasts with other headphone manufacturers that push firmware patches directly to users' devices remotely or via an app.

What practical steps can Dime 3 owners take now?

Are Your Skullcandy Dime 3 Earbuds Letting Strangers Pair to Them Silently?
Are Your Skullcandy Dime 3 Earbuds Letting Strangers Pair to Them Silently?
  • Check your firmware version: Identify if your earbuds are running the vulnerable firmware. This may require consulting product documentation or support resources.
  • Limit Bluetooth usage: Turn off Bluetooth on the earbuds and paired devices when not in use to reduce exposure.
  • Consider upgrading hardware: If security is a priority, upgrading to earbuds with supported and regularly updated firmware is advisable.
  • Practice Bluetooth hygiene: Avoid pairing your earbuds in public spaces or around unknown devices.

What does this mean for users concerned about Bluetooth security?

This flaw underscores the importance of regular, accessible firmware updates for Bluetooth devices, especially those handling audio and microphones. Users should prioritize products from manufacturers that offer prompt, user-friendly security patches.

When a device lacks an update mechanism, vulnerabilities can persist indefinitely, posing ongoing privacy and security risks. Being informed about device firmware status and manufacturer support policies can aid safer purchasing decisions.

React to this story

Related Posts