These earbuds will pair with a stranger, and there is no update you can install
Bluetooth pairing is supposed to require your consent. You hold a button, the light flashes, you tap accept on your phone. The Skullcandy Dime 3 skips that. On 8 September the CERT Coordination Center at Carnegie Mellon published VU#859658, confirming that the Dime 3, model S2DCW, running firmware 1.0.0.28 will accept a Bluetooth pairing request from a device it has never met, with the buds never put into pairing mode and nobody pressing anything on the case.
What that buys an attacker standing within radio range: they can cut in on your existing connection, take over what is playing, reach the headset profile and capture live audio from the earbud microphone. No prior pairing, no physical access, no interaction from you. The flaw is tracked as CVE-2025-20701 and it sits in the Airoha Bluetooth audio SDK, a chipset software kit that shows up across a lot of inexpensive wireless audio gear.
Then the awkward bit. Airoha fixed this in firmware 1.0.0.30, released on 4 August 2025, more than a year ago. Skullcandy has confirmed the Dime 3 cannot be updated through the Skullcandy app, and CERT/CC says there is no consumer-accessible way to move an existing pair from 1.0.0.28 to the fixed version. As of the advisory the centre had received no statement from the vendor. If you own these, you own the broken version.
Practically, that leaves two things. Keep them in the case when you are not listening, because powered down they cannot be paired with. And take a "new device paired" notification seriously rather than shrugging it off as a glitch, since that is the one signal a victim actually gets. Tendvane cannot reach inside a pair of earbuds, but the PC side of your wireless is a different matter: its driver Auto-Update keeps your Bluetooth and Wi-Fi drivers current, which is where fixes on this side of the connection actually land.