Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    SpaceX will try to put Starship in orbit for the first time on September 22

    September 16, 2026

    Canon’s R8 II camera borrowed its styling from a classic SLR film camera

    September 16, 2026

    Bypassing inference bottlenecks: Accelerating complex AI search with Retrieve-for-Train

    September 16, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Wednesday, September 16
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device
    Reviews

    These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device

    myappsplusBy myappsplusSeptember 14, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Researchers warn Skullcandy Dime 3 earbuds on older firmware accept Bluetooth pairing from unknown devices with no user interaction required
    • When leveraged, it can be used to interrupt the owner’s connections, hijack playback, and even capture live microphone audio
    • The vulnerability has been patched in a newer firmware update available only on newer units, does not seem to be addressable for existing earbuds

    Carnegie Mellon University’s CERT Coordination Center has warned Skullcandy’s Dime 3 wireless earbuds will accept a Bluetooth pairing request from a stranger’s device without the owner doing anything.

    The resulting bond is permanent, and the only sign the owner gets is a spoken “new device paired” notification delivered after it has already happened, with zero user interaction to confirm the request.

    The advisory covering the Dime 3 was written by CERT/CC’s Bob Kemerer and credits independent researcher Jacob Nowak, who had posted his findings to the Full Disclosure mailing list in early August after testing it on hardware he owned.

    A fix deployed that covers virtually no existing users

    What makes this worse is that, ironically, while Skullcandy was swift in addressing the issue affecting earbuds running firmware version 1.0.0.28 by rolling out a patched version 1.0.0.30, it seems to address the issue only in newly made units.

    CERT notes that there seem to be no “consumer-accessible” methods to upgrade existing units to the newest firmware because it reportedly has no support

    A product without an update path that is user-accessible essentially means that its software flaws, or in this case, security issues, are here to stay for users who have had the bad luck of buying an earlier unit.

    The underlying vulnerability, CVE-2025-20701, is not new and is not of Skullcandy’s making. It is one of three vulnerabilities that Dennis Heinze and Frieder Steinmetz of the German firm ERNW disclosed in June 2025 at the TROOPERS conference in Heidelberg, affecting Bluetooth systems-on-chip from Taiwan’s Airoha.

    The Dime 3’s Bluetooth identifier names Airoha as its chipset vendor, and while Airoha shipped a fixed SDK to its customers in June 2025 and published its bulletin that August, owners of the earbuds are in a unique situation, to say the least.

    The vulnerability’s severity is disputed: MediaTek (which owns Airoha) assigned it a relatively low 6.7 rating, while CISA’s vulnerability enrichment program later assigned it an 8.8 with a ‘high’ categorization.

    A potential attacker is limited to what the earbuds can access, since the vulnerability is essentially limited to the earbuds, but one could still wreak havoc with that alone. It should allow for more than just disrupting a person’s routine by ‘hijacking’ one’s earbuds by essentially using their microphones on them to record conversations or, in an extreme theoretical case (requiring chaining with other exploits), impersonate the headset and pull contacts, call history, and even pass hands-free commands to a paired smartphone. The latter, however, would require a high technical skill set, being within a few meters of a victim, and a Bluetooth connection turned on on the paired smartphone.

    For now, a vulnerability exists that Skullcandy should have been able to patch, exactly as Apple recently did for its Beats Studio Buds, but a lack of support for any third party apps on the budget earbuds is somewhat annoyingly resulting in an unpatchable vulnerability for existing users.

    Audio Computing Computing Security Cyber Security Pro Security
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Salesforce CEO Marc Benioff says the SaaSpocalypse is ‘crazy nonsense’ – and Jensen Huang agrees with him

    September 16, 2026

    #BookGirlies, rise: here are the upcoming book-to-screen adaptations that I’m genuinely excited about

    September 16, 2026

    Nvidia RTX 5090 GPU prices skyrocket to $9,000 — as fresh RTX 6000 rumor suggests a 2027 launch that fills me with dread

    September 16, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20264 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    New iOS 26 and macOS Tahoe updates fix 30 security vulnerabilities: what you need to know

    myappsplusAugust 18, 2026

    ICE agents can’t wear Meta glasses while they work, official memo warns

    myappsplusAugust 18, 2026

    Ubiquiti sued by Ukrainian families over claims its tech powered Russian battlefield drones

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    New iOS 26 and macOS Tahoe updates fix 30 security vulnerabilities: what you need to know

    August 18, 20260 Views

    ICE agents can’t wear Meta glasses while they work, official memo warns

    August 18, 20260 Views

    Ubiquiti sued by Ukrainian families over claims its tech powered Russian battlefield drones

    August 18, 20260 Views
    Our Picks

    SpaceX will try to put Starship in orbit for the first time on September 22

    September 16, 2026

    Canon’s R8 II camera borrowed its styling from a classic SLR film camera

    September 16, 2026

    Bypassing inference bottlenecks: Accelerating complex AI search with Retrieve-for-Train

    September 16, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.