See how skullcandy compares to other vendors in security performance
CERT/CC put out a warning on this one. Skullcandy Dime 3 earbuds (model S2DCW) running firmware 1.0.0.28 will accept a Bluetooth pairing request from any nearby device with no PIN, no physical access, and no approval prompt. It's CVE-2025-20701, a flaw in the Airoha Bluetooth Audio SDK used across a bunch of earbud brands (same bug affected Beats Studio Buds, fixed by Apple back in June).
Once an attacker's device pairs, it gets trusted status and can auto-reconnect whenever it's in range letting them hijack your audio, kick you off, and pull live mic audio.
You might get a "new device paired" notification, but it's easy to mistake for a random disconnect/reconnect blip.
The rough part: Skullcandy did fix it in firmware 1.0.0.30, but there is currently no way for users to update their earbuds not manually, not through the app. So if you bought a Dime 3 with the vulnerable firmware, you're stuck on it. Basically these things are wide open to close-range hijacking/eavesdropping with no fix in sight for existing units. If you own a pair, worth checking your firmware version and maybe not trusting the mic for anything sensitive until Skullcandy sorts out an update path.