Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

WPair Scanner Released to Detect WhisperPair Flaw in Google’s Fast Pair Protocol

An open-source Android application has been developed to identify and test devices vulnerable to CVE-2025-36911, a critical authentication bypass flaw in Google's Fast Pair Bluetooth protocol.

An open-source Android application has been developed to identify and test devices vulnerable to CVE-2025-36911, a critical authentication bypass flaw in Google's Fast Pair Bluetooth protocol.

This vulnerability, known as WhisperPair, affects millions of Bluetooth audio devices globally, enabling unauthorized pairing and potentially granting access to microphones without user consent.

CVE-2025-36911 highlights a significant cryptographic weakness in the Fast Pair Key-Based Pairing mechanism. The vulnerability arises from missing signature verification on pairing requests and absent user confirmation requirements, allowing attackers to establish persistent Bluetooth connections to vulnerable devices.

The attack chain involves BLE scanning for devices broadcasting the 0xFE2C Fast Pair service UUID, followed by key-based pairing bypass, and concludes with Bluetooth Classic bonding that provides permanent audio profile access.

Researchers from KU Leuven's COSIC and DistriNet groups discovered the vulnerability through systematic protocol analysis. The flaw allows attackers to write persistent Account Keys, enabling covert device tracking through Google's Find Hub Network infrastructure.

Notably, the WPair implementation deliberately excludes FMDN provisioning functionality to prevent weaponization as stalkerware, demonstrating responsible disclosure principles.

The tool offers security researchers three operational modes: vulnerability scanning for unpatched devices, non-invasive testing to determine patch status without triggering pairing, and proof-of-concept exploitation for authorized security assessments.

Post-exploitation, the application enables Hands-Free Profile audio access, allowing real-time microphone listening and M4A format recording capabilities. The BLE scanner discovers Fast Pair devices in pairing mode while detecting vulnerable implementations through cryptographic handshake analysis.

Affected manufacturers include JBL, Harman Kardon, Sony (select models), and Marshall, with numerous additional vendors still deploying vulnerable implementations.

CVE-2025-36911 highlights a significant cryptographic weakness in the Fast Pair Key-Based Pairing mechanism.
Laura Mitchell · Thehackingpost

Feature Description Status Use Case

BLE Scanner Discovers Fast Pair devices broadcasting 0xFE2C service UUID Active Device inventory and reconnaissance

Vulnerability Tester Non-invasive check to determine if device is patched against CVE-2025-36911 Active Risk assessment without triggering pairing

Exploit Demonstration Full proof-of-concept exploitation for authorized security testing Active Authorized vulnerability validation

HFP Audio Access Demonstrates microphone access via Hands-Free Profile post-exploitation Active Impact demonstration

Live Listening Real-time audio streaming to phone speaker Active Proof-of-concept microphone access

Advertisement

Recording Capture and save audio streams as M4A files Active Evidence collection and testing

Installation requires Android 8.0 or higher with Bluetooth LE support; the application is available via GitHub releases or direct compilation from source code.

The vulnerability poses a threat to millions of daily users relying on Fast Pair for seamless Bluetooth device pairing. Attackers exploiting WhisperPair can establish persistent connections to victim headphones without explicit consent, accessing microphone streams for eavesdropping and establishing location tracking infrastructure through Account Key persistence.

Unlike traditional Bluetooth exploits requiring proximity during pairing, CVE-2025-36911 enables post-pairing compromise of already-configured devices.

Device manufacturers face urgent remediation requirements through firmware updates implementing cryptographic signature verification and explicit user confirmation mechanisms.

Users should monitor vendor security advisories and apply patches promptly, particularly for frequently-used audio devices.

The WPair toolkit represents a significant advance in defensive research capabilities, enabling systematic vulnerability identification across heterogeneous device ecosystems. Responsible disclosure principles embedded within the codebase specifically excluding FMDN tracking functionality establish ethical boundaries for security research while maintaining sufficient technical depth for vulnerability remediation validation.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories