WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected
A significant vulnerability has been identified in Google's Fast Pair protocol, allowing unauthorized access and control of Bluetooth audio devices, as well as potential user tracking without consent.
A significant vulnerability has been identified in Google's Fast Pair protocol, allowing unauthorized access and control of Bluetooth audio devices, as well as potential user tracking without consent.
Researchers from KU Leuven discovered this vulnerability, known as CVE-2025-36911 or WhisperPair, which affects numerous wireless earbuds, headphones, and speakers from manufacturers such as Sony, Anker, Google, Jabra, JBL, Logitech, Marshall, Nothing, OnePlus, Soundcore, and Xiaomi.
Google has classified this vulnerability as critical and awarded a $15,000 bounty to the researchers. The issue arises from an improper implementation of the Fast Pair protocol .
Critical Flaw in Fast Pair Implementation
The Fast Pair specification requires Bluetooth accessories to ignore pairing requests when not in pairing mode. However, many devices fail to enforce this security check, enabling unauthorized devices to initiate pairing without user interaction.
Attackers can exploit this vulnerability using standard Bluetooth-capable devices such as laptops, smartphones, or Raspberry Pi . Successful attacks occur in approximately 10 seconds and within a 14-meter range, without requiring physical access to the device.
Google has classified this vulnerability as critical and awarded a $15,000 bounty to the researchers.
Once paired, attackers can control the audio accessory, possibly playing audio at high volumes or recording through the microphone. Furthermore, if an accessory is unpaired with an Android device, attackers may add it to their Google account and track the user's location via the Find Hub network.
This vulnerability impacts users across various platforms, as the flaw is within the accessories, not the smartphones. iPhone users with vulnerable Bluetooth devices are equally at risk. Since Fast Pair functionality cannot be disabled on accessories, users outside the Android ecosystem remain vulnerable.
The WhisperPair findings were reported to Google in August 2025, with a 150-day disclosure period for manufacturers to release security patches. Installing firmware updates from device manufacturers is the only effective mitigation.
While some manufacturers have released patches, updates may not yet be available for all affected devices. Users are advised to check their accessory's manual for update instructions and verify patch availability with manufacturers.
The WhisperPair vulnerability highlights a systemic oversight, as affected devices passed both manufacturer quality assurance and Google's certification process before reaching the market.
Based on reporting by Cyber Security News.
