VU#859658: Skullcandy Dime 3 w... Note

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

Skullcandy Dime 3 wireless earbuds, firmware version 1.0.0.28, have a vulnerability allowing unauthorized Bluetooth Classic pairing. These earbuds accept pairing requests from unpaired devices without any user interaction or confirmation. The vulnerability stems from the Airoha chipset used in the earbuds.An attacker within Bluetooth range can pair with the earbuds without prior connection or physical access. They can send a direct pairing request without a PIN or passkey. The earbuds' NoInputNoOutput capability allows this immediate bonding.Once paired, the attacker's device becomes trusted and can automatically reconnect. This enables audio hijacking, interrupting the legitimate user's connection. The only notification for the user is an audible alert after the unauthorized pairing has occurred.Beyond audio, an attacker could potentially access other services on the earbuds. They can also utilize the Hands-Free/Headset profile to capture live microphone audio. The vendor has released a patch in firmware version 1.0.0.30.However, Skullcandy Dime 3 earbuds do not support firmware updates via their application. This means existing units with the vulnerable firmware cannot be updated by customers. There are currently no known methods for users to update their existing devices to the patched firmware.