Researchers have raised concerns about a security flaw in older versions of Skullcandy’s Dime 3 wireless earbuds. The issue allows the earbuds to accept Bluetooth pairing requests from unknown devices without requiring any input or confirmation from the user. Once paired, the attacker can disrupt the owner’s existing Bluetooth connections, take control of audio playback, and even capture live microphone audio. This vulnerability was identified by Carnegie Mellon University’s CERT Coordination Center and attributed to a flaw in the Bluetooth chip used in the earbuds. The vulnerability was first reported by independent researcher Jacob Nowak, who tested it on his own Dime 3 earbuds and shared his findings on the Full Disclosure mailing list in early August. CERT/CC analyst Bob Kemerer confirmed the issue and highlighted that the pairing notification is only a spoken message that appears after the pairing has already occurred, leaving users with no opportunity to stop or confirm the connection. Skullcandy released a firmware update (version 1.0.0.30) in response to the flaw, which fixes the issue in newer units. However, this update does not apply to existing earbuds. According to reports, there is no way for current users to manually update the firmware through the companion app or any other accessible method. This means that users who purchased the Dime 3 before the update is available are left vulnerable. The underlying issue, known as CVE-2025-20701, was not created by Skullcandy but is tied to the Bluetooth chip used in the Dime 3, manufactured by Airoha, a subsidiary of MediaTek. The vulnerability was disclosed earlier this year by researchers from the German firm ERNW. While Airoha provided a software update to its customers, the Dime 3 users are unable to apply the fix due to a lack of firmware update support on the device. This has sparked debate over the severity of the flaw, with some rating systems giving it a high risk level, while others consider it less critical. Regardless, the vulnerability allows an attacker to potentially eavesdrop on conversations or disrupt the user’s experience, though more complex attacks would require additional technical expertise and proximity.