← Blog · · df00tech

CERT/CC Warns Skullcandy Dime 3 Earbuds Accept Silent Bluetooth Pairing Requests

security-news advisory

CERT/CC (Carnegie Mellon University's CERT Coordination Center) has published an advisory stating that Skullcandy Dime 3 wireless earbuds will accept Bluetooth pairing requests from nearby unpaired devices without requiring any user interaction to approve the connection.

Why It Matters

Bluetooth pairing is normally a trust boundary: a device shouldn't join a paired session without the owner confirming it in some way (a button press, a PIN, a prompt). If the Dime 3 accepts pairing requests automatically, an attacker within Bluetooth range could potentially connect to the earbuds without the owner's knowledge or consent. Depending on what an attached device can do once paired — such as injecting or intercepting audio — this could enable eavesdropping or disruption of the audio channel. The report does not specify the full technical impact beyond the pairing weakness itself, so defenders should avoid assuming capabilities not confirmed in the advisory.

What Defenders Should Watch For

  • Treat this as a physical/proximity-based Bluetooth exposure rather than a remote network threat — risk is highest in crowded public spaces (transit, offices, conferences).
  • Organizations with BYOD or wearable-device policies should inventory whether Skullcandy Dime 3 or similar low-cost earbuds with weak pairing controls are in use.
  • Where feasible, disable Bluetooth discoverability/pairing mode on the earbuds when not actively pairing, and avoid leaving them in a pairable state in public areas.
  • Watch vendor channels for a firmware update or official advisory response from Skullcandy, since CERT/CC advisories typically precede or accompany vendor remediation guidance.
  • This is a hardware/firmware-level Bluetooth stack issue, not something addressable via SIEM detection content — there is no CVE or vendor patch confirmed at time of writing.

Developing Story

This item is based on a CERT/CC advisory as reported by BleepingComputer and is still developing; no CVE identifier or vendor remediation timeline has been confirmed at this time. For the latest details, see the original report: BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.