:

SKULLCANDY DIME 3 EARBUDS VULNERABLE TO BLUETOOTH HIJACKING

INDUSTRY DESK1 MIN READ
WED, SEP 9, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Carnegie Mellon University's CERT Coordination Center has identified a critical security flaw in Skullcandy Dime 3 earbuds that allows nearby devices to pair without user approval. Attackers can exploit this vulnerability to hijack the earbuds and potentially access connected devices.

The CERT/CC warning reveals that Skullcandy Dime 3 earbuds automatically accept Bluetooth pairing requests from unpaired devices in proximity without requiring any user interaction or confirmation. This flaw creates an entry point for attackers to pair malicious devices and potentially intercept audio, inject commands, or access connected smartphones and computers. Users with Skullcandy Dime 3 earbuds are at immediate risk when the devices are in pairing mode or discoverable state. The vulnerability affects the earbuds' core pairing mechanism and bypasses standard Bluetooth security protocols. Skullcandy has not yet released a firmware update or official statement addressing the vulnerability. Users are advised to keep their earbuds in non-discoverable mode when not actively pairing and to monitor firmware updates from the manufacturer. Anyone experiencing unauthorized pairing attempts should discontinue use until a patch is available.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Read the Docs, the popular documentation hosting platform, recently experienced a significant distributed denial-of-service (DDoS) attack. The platform has published technical details about the incident and its response.

JUST NOWAI Desk

Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC), is actively being exploited in attacks.

JUST NOWSecurity Desk

Healthcare company AdaptHealth has confirmed that a cyberattack discovered in July compromised data belonging to 4.1 million people. The breach was attributed to the ShinyHunters threat group.

JUST NOWSecurity Desk

Two major US law firms have fallen victim to cyber extortion attacks, with threat actors obtaining and publishing private client documents. The incidents highlight ongoing security vulnerabilities in the legal sector.

5H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.