Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

WPair – Scanner Tool to Detect WhisperPair Flaw in Google’s Fast Pair Protocol

WPair is an Android application developed to identify and demonstrate the CVE-2025-36911 vulnerability, which affects millions of Bluetooth audio devices worldwide. This tool addresses a critical authentication bypass flaw discovered in Google's Fast…

WPair is an Android application developed to identify and demonstrate the CVE-2025-36911 vulnerability, which affects millions of Bluetooth audio devices worldwide. This tool addresses a critical authentication bypass flaw discovered in Google's Fast Pair protocol, known as WhisperPair.

The vulnerability, CVE-2025-36911, is due to improper enforcement of pairing mode verification in Fast Pair implementations across various manufacturers and chipsets.

The application offers three core scanning and testing modes:

BLE Scanner: Identifies nearby Fast Pair devices by detecting devices broadcasting the 0xFE2C service UUID. Vulnerability Tester: Conducts non-invasive checks to determine patch status without establishing connections. Exploit Demo: Demonstrates the complete attack chain, including key-based pairing bypass, BR/EDR address extraction, and Bluetooth Classic bonding.

Feature Description

BLE Scanner Detects Fast Pair devices in real time

Vulnerability Tester Checks CVE-2025-36911 patch status safely

Exploit Demo Proof-of-concept for authorized testing

HFP Audio Access Shows microphone access after exploit

Live Listening Streams audio to phone instantly

This tool addresses a critical authentication bypass flaw discovered in Google's Fast Pair protocol, known as WhisperPair.
Jason Ford · Thehackingpost

Audio Recording Saves captured audio for analysis

Device Status Detection Flags devices in pairing mode

Key-Based Bypass Demonstrates Fast Pair auth bypass

BR/EDR Extraction Retrieves Bluetooth Classic addresses

Classic Bonding Creates persistent audio connections

Account Key Persistence Demonstrates long-term device tracking

Post-exploitation capabilities include accessing the Hands-Free Profile for microphone functionality. Users can enable live audio streaming directly to their phone speaker or save captured audio as M4A files for forensic analysis.

The vulnerability allows attackers to hijack devices without authorization, control audio playback, record conversations, and potentially establish persistent tracking.

Advertisement

Technical Requirements and Installation Options

Category Details

Minimum Android Version Android 8.0 (API 26) or higher

Bluetooth Support Bluetooth Low Energy (BLE) required

Permissions Location permissions (or Nearby Devices on Android 13+)

Installation – APK Download pre-compiled APK from Releases

Installation – Source Build Build from source using Gradle

Google classified this issue as critical and awarded researchers a $15,000 bounty. The disclosure window ended in January 2026, and manufacturers are releasing patches.

WPair requires Android 8.0 or higher with Bluetooth LE support and appropriate location permissions. The application is available both as a precompiled APK and as a compiled source via Gradle.

The tool is significant for vulnerability assessment in the IoT audio ecosystem, enabling manufacturers and security teams to identify affected devices requiring immediate firmware updates.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories