A critical Bluetooth pairing vulnerability in Skullcandy Dime 3 wireless earbuds allows attackers to silently pair with the device, disrupt legitimate audio sessions, and capture live microphone audio without user interaction. The issue, identified in CERT Coordination Center Vulnerability Note VU#859658, impacts Skullcandy Dime 3 earbuds (model S2DCW) running firmware version 1.0.0.28. Attackers need only be within Bluetooth radio range of the targeted earbuds; they do not require prior pairing, physical access, PIN, passkey, or owner approval.
The earbuds accept Bluetooth Classic (BR/EDR) pairing requests from previously unpaired devices, even when they have not been explicitly placed into pairing mode. However, affected Dime 3 units reportedly initiate direct pairing with a discovered Bluetooth address and automatically complete bonding.
A nearby attacker who successfully pairs with the earbuds can access these services and capture live audio from the earbuds’ microphone, potentially exposing conversations, calls, or ambient sounds. As a consequence, customers with devices running on a vulnerable firmware version currently have no known consumer-accessible method to install the updated firmware release. Until an update mechanism or replacement option is made available, users should exercise caution when using the earbuds in public or shared areas where an attacker could operate within Bluetooth range.












