mediumOther

Skullcandy Dime 3 Bluetooth Auto-Pairing Vulnerability

First seen Sep 10, 2026 · Updated Sep 10, 2026

bluetoothiothardware-vulnerabilityproximity-attackconsumer-device

CERT/CC has disclosed that Skullcandy Dime 3 wireless earbuds will accept Bluetooth pairing requests from any nearby device without requiring user confirmation. This flaw could allow an attacker within Bluetooth range to eavesdrop on audio or hijack the connection without the victim's knowledge or consent.

Technical Analysis

The vulnerability stems from the Dime 3's Bluetooth pairing implementation, which lacks a user-interaction requirement (such as a confirmation prompt or PIN entry) before establishing a connection with unpaired devices, deviating from standard Bluetooth Secure Simple Pairing (SSP) best practices. An attacker within radio range could exploit this to force-pair with the earbuds, potentially intercepting audio streams, disrupting playback, or maintaining persistent unauthorized access to the device. No authentication or authorization check appears to gate the pairing handshake, making this a low-complexity proximity-based attack. This is a consumer hardware/IoT accessory issue with no direct connection to AI agent systems, LLM tool use, or RAG pipelines, and no plausible agent-relevant impact has been identified.

Affected Systems

Skullcandy Dime 3 wireless earbuds (all units running the default/shipped Bluetooth firmware as of disclosure)

Indicators of Compromise

  • Not applicable — hardware design flaw, no file-based or network IOCs identified

Remediation Steps

  1. 1

    Apply firmware update

    Check for and install any firmware update released by Skullcandy that enforces user confirmation for Bluetooth pairing requests.

  2. 2

    Limit exposure

    Disable Bluetooth discoverability/pairing mode on the earbuds when not actively pairing with a new device.

  3. 3

    Monitor connected devices

    Regularly review paired device lists on host phones/computers to detect unauthorized Bluetooth connections.

  4. 4

    Vendor engagement

    Organizations issuing these devices to staff should contact Skullcandy support for remediation guidance and consider alternative hardware until a fix is confirmed.

Industries Most Exposed

consumer electronicsretail

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.