WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected
ID: bc4dad4a-dcc8-5280-b8dc-c68f2f2b396d
STIX ID: report--bc4dad4a-dcc8-5280-b8dc-c68f2f2b396d
Feed Name: cybersecurityNews.com
Threat Score
A critical Fast Pair implementation flaw (CVE-2025-36911, “WhisperPair”) lets attackers initiate pairing with Bluetooth audio accessories without user consent, allowing remote control, eavesdropping, and location tracking via Google’s Find Hub; the bug affects hundreds of millions of devices from major vendors and the only effective mitigation is firmware updates from manufacturers, which are being rolled out but are not yet universal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
