Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

Summary

Skullcandy Dime 3 wireless earbuds are vulnerable to Bluetooth hijacking. The earbuds accept pairing requests from nearby unpaired devices without user interaction, potentially allowing attackers to intercept audio or inject malicious commands. This vulnerability could enable unauthorized access to sensitive information transmitted through the earbuds.

IFF Assessment

FOE

The vulnerability allows for unauthorized access and potential interception of sensitive information, which is detrimental to user security.

Severity

7.5 High (AI Estimated)

The vulnerability allows for a low-complexity attack (no privileges required, no user interaction needed for initial connection) that can lead to significant data leakage (confidentiality) and potential modification of transmitted data (integrity). The impact on availability is likely low unless the hijacking is used to disrupt functionality.

Defender Context

This highlights a common vulnerability in IoT devices relying on Bluetooth, where relaxed pairing mechanisms can be exploited. Defenders should be aware of such vulnerabilities in connected audio devices and advise users to be cautious about pairing them in public spaces or near unknown devices. Manufacturers need to implement stronger authentication and user consent mechanisms for Bluetooth pairing.

Read Full Story →