Dime 3 model S2DCW earbuds running firmware 1.0.0.28 are affected. Skullcandy fixed the issue in firmware 1.0.0.30, but the provided information states that users currently have no way to install firmware updates on existing earbuds.
An attacker only needs a Bluetooth-capable device within range of the earbuds. No PIN, physical access, or approval prompt is required for the pairing request.
The attacker's device receives trusted status and can reconnect automatically whenever it is nearby. This can allow audio hijacking, disconnecting the legitimate user, and access to live microphone audio.
The earbuds may display a "new device paired" notification. However, this can be easily confused with an ordinary disconnect or reconnect event, so it is not a reliable indicator on its own.
Check the firmware version and treat the microphone as unsuitable for sensitive conversations if the device is running the vulnerable firmware. The provided information does not identify a user-applied remediation for affected existing units.