WPair – Scanner Tool to Detect WhisperPair Flaw in Google’s Fast Pair Protocol
WPair is an Android application developed to identify and demonstrate the CVE-2025-36911 vulnerability, which affects millions of Bluetooth audio devices worldwide. This tool addresses a critical authentication bypass flaw discovered in Google's Fast…
WPair is an Android application developed to identify and demonstrate the CVE-2025-36911 vulnerability, which affects millions of Bluetooth audio devices worldwide. This tool addresses a critical authentication bypass flaw discovered in Google's Fast Pair protocol, known as WhisperPair.
The vulnerability, CVE-2025-36911, is due to improper enforcement of pairing mode verification in Fast Pair implementations across various manufacturers and chipsets.
The application offers three core scanning and testing modes:
BLE Scanner: Identifies nearby Fast Pair devices by detecting devices broadcasting the 0xFE2C service UUID. Vulnerability Tester: Conducts non-invasive checks to determine patch status without establishing connections. Exploit Demo: Demonstrates the complete attack chain, including key-based pairing bypass, BR/EDR address extraction, and Bluetooth Classic bonding.
Feature Description
BLE Scanner Detects Fast Pair devices in real time
Vulnerability Tester Checks CVE-2025-36911 patch status safely
Exploit Demo Proof-of-concept for authorized testing
HFP Audio Access Shows microphone access after exploit
Live Listening Streams audio to phone instantly
This tool addresses a critical authentication bypass flaw discovered in Google's Fast Pair protocol, known as WhisperPair.
Audio Recording Saves captured audio for analysis
Device Status Detection Flags devices in pairing mode
Key-Based Bypass Demonstrates Fast Pair auth bypass
BR/EDR Extraction Retrieves Bluetooth Classic addresses
Classic Bonding Creates persistent audio connections
Account Key Persistence Demonstrates long-term device tracking
Post-exploitation capabilities include accessing the Hands-Free Profile for microphone functionality. Users can enable live audio streaming directly to their phone speaker or save captured audio as M4A files for forensic analysis.
The vulnerability allows attackers to hijack devices without authorization, control audio playback, record conversations, and potentially establish persistent tracking.
Technical Requirements and Installation Options
Category Details
Minimum Android Version Android 8.0 (API 26) or higher
Bluetooth Support Bluetooth Low Energy (BLE) required
Permissions Location permissions (or Nearby Devices on Android 13+)
Installation – APK Download pre-compiled APK from Releases
Installation – Source Build Build from source using Gradle
Google classified this issue as critical and awarded researchers a $15,000 bounty. The disclosure window ended in January 2026, and manufacturers are releasing patches.
WPair requires Android 8.0 or higher with Bluetooth LE support and appropriate location permissions. The application is available both as a precompiled APK and as a compiled source via Gradle.
The tool is significant for vulnerability assessment in the IoT audio ecosystem, enabling manufacturers and security teams to identify affected devices requiring immediate firmware updates.
Based on reporting by Cyber Security News.
