logo

WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected

ID: bc4dad4a-dcc8-5280-b8dc-c68f2f2b396d

STIX ID: report--bc4dad4a-dcc8-5280-b8dc-c68f2f2b396d

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical Fast Pair implementation flaw (CVE-2025-36911, “WhisperPair”) lets attackers initiate pairing with Bluetooth audio accessories without user consent, allowing remote control, eavesdropping, and location tracking via Google’s Find Hub; the bug affects hundreds of millions of devices from major vendors and the only effective mitigation is firmware updates from manufacturers, which are being rolled out but are not yet universal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.