Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected

A significant vulnerability has been identified in Google's Fast Pair protocol, allowing unauthorized access and control of Bluetooth audio devices, as well as potential user tracking without consent.

A significant vulnerability has been identified in Google's Fast Pair protocol, allowing unauthorized access and control of Bluetooth audio devices, as well as potential user tracking without consent.

Researchers from KU Leuven discovered this vulnerability, known as CVE-2025-36911 or WhisperPair, which affects numerous wireless earbuds, headphones, and speakers from manufacturers such as Sony, Anker, Google, Jabra, JBL, Logitech, Marshall, Nothing, OnePlus, Soundcore, and Xiaomi.

Google has classified this vulnerability as critical and awarded a $15,000 bounty to the researchers. The issue arises from an improper implementation of the Fast Pair protocol .

Critical Flaw in Fast Pair Implementation

The Fast Pair specification requires Bluetooth accessories to ignore pairing requests when not in pairing mode. However, many devices fail to enforce this security check, enabling unauthorized devices to initiate pairing without user interaction.

Attackers can exploit this vulnerability using standard Bluetooth-capable devices such as laptops, smartphones, or Raspberry Pi . Successful attacks occur in approximately 10 seconds and within a 14-meter range, without requiring physical access to the device.

Google has classified this vulnerability as critical and awarded a $15,000 bounty to the researchers.
Paige Monroe · Thehackingpost

Once paired, attackers can control the audio accessory, possibly playing audio at high volumes or recording through the microphone. Furthermore, if an accessory is unpaired with an Android device, attackers may add it to their Google account and track the user's location via the Find Hub network.

This vulnerability impacts users across various platforms, as the flaw is within the accessories, not the smartphones. iPhone users with vulnerable Bluetooth devices are equally at risk. Since Fast Pair functionality cannot be disabled on accessories, users outside the Android ecosystem remain vulnerable.

The WhisperPair findings were reported to Google in August 2025, with a 150-day disclosure period for manufacturers to release security patches. Installing firmware updates from device manufacturers is the only effective mitigation.

Advertisement

While some manufacturers have released patches, updates may not yet be available for all affected devices. Users are advised to check their accessory's manual for update instructions and verify patch availability with manufacturers.

The WhisperPair vulnerability highlights a systemic oversight, as affected devices passed both manufacturer quality assurance and Google's certification process before reaching the market.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories