← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 14:42via CERT/CC Vulnerability Notes

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

Brief

Overview

Skullcandy Dime 3 wireless earbuds, running firmware version 1.

  • 0. 28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner.

Description

The Skullcandy Dime 3 (Model S2DCW) wireless earbuds, running firmware version 1.

  • 0. 28, accept a new Bluetooth Classic (BR/EDR) pairing request from a previously unpaired device without the device being placed into pairing mode by the owner and without physical confirmation on the earbuds. The device's Bluetooth PnP modalias identifies the chipset vendor as Airoha Technology Corp.

(Bluetooth SIG company ID 0x0094).

Read more on CERT/CC Vulnerability Notes