Image credit: Skullcandy
If you own a pair of Skullcandy Dime 3 earbuds, someone standing near you could connect to them without asking, eavesdrop on your audio, and you'd only find out after it already happened.
That's the warning in a new advisory from CERT/CC, a federally funded vulnerability watchdog based at Carnegie Mellon University. According to CERT/CC, the Dime 3 will accept a Bluetooth connection from a nearby stranger's device on its own, with no button press, no PIN, and no need to touch the earbuds or their case.
All an attacker needs is to be within Bluetooth range, generally about 30 feet. Once connected, their device gets treated as trusted and can reconnect automatically later. CERT/CC says that's enough to hijack the audio or listen in through the earbuds' microphone. The only warning is a "new device paired" chime, and it plays after the stranger is already connected.
Skullcandy isn't the first brand caught up in this. The earbuds use an Airoha Bluetooth chip, the same chip Techlicious reported on in June as putting roughly 30 headphone and earbud models at risk, including ones from Sony, Bose, JBL, Marshall, and Beats. Those brands have since fixed the problem with a firmware update.
Skullcandy says it has a fix too: the company told CERT/CC that a newer firmware version patches the flaw. But the Dime 3 can't get firmware updates through the Skullcandy app, and CERT/CC says there's currently no way for owners to install that fix themselves.
If you own a pair of Dime 3 earbuds, it's worth thinking about where you wear them. Pay attention if you hear that "new device paired" chime when you haven't paired anything yourself. Neither CERT/CC's advisory nor anything public from Skullcandy provides a timeline for a real fix. So for now, awareness is the only protection you have.
Read more: The best open ear earbuds of 2026, tested