By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Skullcandy Dime 3 Earbuds Vulnerable to Bluetooth Hijacking
Carnegie Mellon University's CERT Coordination Center (CERT/CC) has issued a warning regarding a significant security vulnerability in Skullcandy Dime 3 wireless earbuds. The vulnerability allows Bluetooth pairing requests from nearby, unpaired devices to be accepted without any user interaction. This means an attacker within Bluetooth range could potentially pair their device with the earbuds, gaining control over them. The CERT/CC identified this issue as a critical security flaw that could lead to various malicious activities. The specific vulnerability lies in how the earbuds handle incoming Bluetooth pairing requests. Typically, Bluetooth pairing requires a confirmation step on both devices to ensure the user intends to connect. However, the Dime 3 earbuds, according to the CERT/CC advisory, bypass this crucial confirmation step. This bypass enables an attacker to initiate a pairing process and, if successful, connect their own device to the earbuds. Once paired, an attacker could potentially intercept audio streams, inject unwanted audio, or even attempt to use the earbuds' microphone for eavesdropping, depending on the device they are paired with and the operating system's permissions. The CERT/CC has not yet released specific technical details on how to exploit this vulnerability, but the advisory highlights the inherent risk of unauthorized access. The advisory, published on May 23, 2024, urges users to be aware of their surroundings and the potential for nearby devices to attempt unauthorized pairing. While the CERT/CC has not specified a CVE identifier for this vulnerability, its classification as a critical security flaw underscores the potential impact on user privacy and security. Skullcandy has not yet issued a public statement or released a firmware update to address this vulnerability. Users are advised to exercise caution when using the Skullcandy Dime 3 earbuds in public or crowded areas where malicious actors might be present. The lack of a user-initiated confirmation for Bluetooth pairing is a fundamental security oversight that could have far-reaching implications for the privacy of individuals using these earbuds. This vulnerability could also be exploited to gain access to the host device if the earbuds have access to certain permissions or functionalities on the connected smartphone or computer. The CERT/CC's warning serves as a reminder of the ongoing security challenges in the rapidly expanding market of wireless audio devices and the importance of robust security protocols in consumer electronics. Further details regarding mitigation strategies or potential firmware updates are expected to be released as the situation develops.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.